Outsourcing Management in Accordance with MaRisk and DORA: What Matters Now

Why Outsourcing Is Not a Relinquishment of Responsibility

Outsourcing Management 2026 – Managing Service Providers While Retaining Responsibility

Why Responsibility Isn't Outsourced

Companies outsource processes because specialized service providers can handle many tasks faster, more scalably, or simply better. This applies to accounting processes as well as compliance tasks, cloud services, and aspects of risk management.

However, the risks do not disappear when the task is completed. And certainly not the responsibility. It remains with management and comes back into play at the latest when the service provider fails to deliver, a contract has loopholes, or the regulatory authority raises questions.

Effective outsourcing management therefore ensures that external services are managed throughout their entire lifecycle: from initial assessment and risk analysis through the contract to ongoing monitoring and an orderly exit.


Outsourcing Management in Accordance with MaRisk and DORA for the Management of External Service Providers

What does outsourcing management mean?

Outsourcing management is the central organizational oversight of outsourced activities and processes. It brings together business units, procurement, risk management, compliance, information security, data protection, internal audit, and senior management.

His job is not to circulate as many forms as possible between these departments. Rather, what matters most is that the company be able to provide a reliable answer at any time:

  • Which services are provided by which service providers?
  • Which outsourcing arrangements are material?
  • What risks and dependencies exist?
  • What other outsourcing arrangements or subcontractors are used?
  • Are the agreed-upon services actually being provided?
  • What happens in the event of a breach of contract or termination of the contract?

This is what distinguishes outsourcing management from traditional procurement. Procurement acquires a service. Outsourcing management assesses and monitors the impact of that service on the business organization and its risk profile.

For which companies is outsourcing management particularly relevant?

Specific regulatory requirements apply to companies in the financial sector. Depending on the applicable regulatory framework, these include, among others, credit and financial services institutions, payment and e-money institutions, securities firms, and insurance companies.

The legal basis varies by industry. For credit institutions, § 25b of the German Banking Act (KWG) and the MaRisk are particularly relevant. Payment institutions must comply with, among other things, § 26 of the German Payment Services Act (ZAG), while insurance companies must adhere to the outsourcing requirements under § 32 of the German Insurance Act (VAG). In addition, there are European requirements such as DORA for third-party ICT services.

Therefore, not every ordinary limited liability company (GmbH) automatically requires regulatory outsourcing management. However, even outside of regulated industries, structured service provider management makes sense as soon as critical business processes, sensitive data, or significant operational dependencies are involved.

Outsourcing Management Under the 9th Amendment to MaRisk

As of June 30, 2026, BaFin Circular 06/2026 (BA)—and thus the 9th amendment to MaRisk—applies to the affected institutions.

The new version is more focused on principles and proportionality. However, less detailed text does not mean that outsourced entities are now allowed to supervise themselves.

AT 9 MaRisk continues to require a risk-based classification of outsourcing arrangements. For significant outsourcing arrangements, this includes, in particular, appropriate contractual provisions, ongoing performance monitoring, consideration of further outsourcing, and realistic options for termination.

Depending on the nature, scope, and complexity of the outsourcing activities, a central outsourcing management function must be established. Its responsibilities include, in particular:

  • the development of appropriate control and monitoring processes,
  • the complete documentation, including subcontracting,
  • maintaining the transfer register,
  • support for the academic departments,
  • the coordination and review of risk analyses,
  • Regular and ad hoc reporting to management.

One notable change from the previous version of MaRisk is that the explicit requirement to appoint a central outsourcing officer within the institution is no longer included in AT 9 of the new version. However, centralized outsourcing management remains mandatory to the extent that the nature, scope, and complexity of the outsourcing arrangements so require.

This makes the organizational structure more flexible. Responsibility doesn’t diminish; it simply gains a little more leeway—and, unfortunately, with that comes fewer opportunities to hide behind a clause in the text.

MaRisk and DORA: Two Regulatory Areas, One Risk Profile

Another important change concerns ICT services. MaRisk 2026 explicitly clarifies that outsourced or third-party ICT services subject to third-party risk management under Articles 28 through 30 of DORA do not fall within the scope of AT 9 MaRisk.

DORA’s independent third-party ICT risk management framework applies to such services. Its scope is broader than the traditional definition of outsourcing. For example, it may also cover ICT services that were previously treated as other external procurements.

Among other things, DORA requires an upfront risk assessment and due diligence, defined contract terms, an information register, ongoing monitoring of ICT service providers, and exit strategies. For ICT services that support critical or important functions, Delegated Regulation (EU) 2024/1773 specifies requirements for the entire contract lifecycle.

In practice, MaRisk outsourcing management and DORA third-party management should therefore not be organized as two separate, unrelated systems. The legal allocation must be clearly separated. Inventories, responsibilities, risk analyses, and reporting channels should, however, be aligned.

Anyone interested in delving deeper into the DORA framework will find further insight in the K11 article “DORA in the Financial Sector: Why Digital Resilience Is More Than Just IT Security.”

The Six Phases of Effective Outsourcing Management

Robust outsourcing management supports not only the conclusion of the contract but also the entire lifecycle of the outsourced service.

1. Record and Categorize Inventory

First, all relevant outsourced services must be identified. Next, it must be determined whether the arrangement constitutes a regulatory outsourcing, another type of outsourcing, or an ICT service under DORA.

2. Assess Risks and Materiality

The risk analysis examines, among other things, operational dependencies, concentration risks, data protection and information security, service delivery locations, subcontractors, and the impact of a failure.

3. Choose service providers carefully

Before awarding a contract, the provider’s professional qualifications, financial stability, personnel and technical resources, control systems, and emergency preparedness should be reviewed. A compelling presentation is helpful, but it is no substitute for a control system.

4. Draft the contract appropriately

Service descriptions, service levels, rights to information and audit, data protection, security requirements, subcontracting, termination rights, and exit support services must be tailored to the specific risk situation.

5. Continuously monitor performance and risks

Once the agreement is signed, the actual management process begins. This includes appropriate performance and risk indicators, regular reviews, addressing deviations, and established escalation procedures.

6. Prepare to Exit

In the case of significant outsourcing, institutions must assess how the service can be transferred to another provider or brought back in-house. An exit strategy that merely states that a solution will be found in an emergency is more like a wish list.

Common Weaknesses in Practice

Problems often arise not from a complete lack of documentation, but from a lack of connections between them. Purchasing maintains a list of service providers, Compliance maintains an outsourcing registry, and IT maintains a DORA information registry. All three are properly maintained but know of each other only by hearsay.

Other common vulnerabilities include:

  • Contracts are signed before the risk analysis is complete.
  • Offshoring and subcontractors remain underreported.
  • Performance indicators are agreed upon but not regularly evaluated.
  • The division of responsibilities between the department and the control functions is unclear.
  • Contract changes reach the outsourcing management team too late.
  • Exit plans are in place, but their feasibility has never been assessed.
  • Management receives data, but no analysis relevant to decision-making.

Effective outsourcing management therefore establishes a standardized process with clear triggers, responsibilities, and escalation procedures.

How External Support Can Take the Pressure Off

Not every institution can maintain a large dedicated team for outsourcing management on a long-term basis. External support can help alleviate the workload when it comes to establishing governance, conducting risk analyses, maintaining registers, monitoring service providers, preparing management reports, or preparing for audits.

K11 Consulting supports companies in establishing, further developing, and operationally implementing outsourcing management. In doing so, existing structures can be adopted, gaps identified, and processes aligned across departments, control functions, and senior management.

Of course, management’s responsibility remains within the company. External support is not intended to overshadow that responsibility, but rather to ensure that it can be carried out in practice.

What Companies Should Be Reviewing Now

  1. Is the list of all transfers out and relevant third-party payments complete?
  2. Are ICT services correctly distinguished in accordance with DORA, and are outsourcing arrangements correctly distinguished in accordance with AT 9 MaRisk?
  3. Are risk analyses, contracts, and registries up to date?
  4. Are there clear lines of responsibility and reliable escalation procedures?
  5. Does management reporting provide information relevant to decision-making?
  6. Are exit strategies and contingency plans feasible in practice?

Conclusion

Outsourcing management begins before the contract is signed and does not end when it is filed away. It combines legal analysis, risk management, contract drafting, service provider oversight, and management reporting into an ongoing process.

The 9th MaRisk Amendment provides greater flexibility in designing processes and more clearly distinguishes traditional outsourcing from third-party ICT risk management under DORA. This is precisely why companies must design their processes thoughtfully. Tasks may be outsourced, but oversight should not.