Discover our new Cybersecurity Report 2025! Free download – valuable insights.
IT security & outsourced activities and processes according to MaRisk AT 9
In the case of larger institutions, which have to manage many types of outsourcing, this is done via central outsourcing management, which prepares an annual report on all material outsourced services and processes for the supervisory authority. BaFin also stipulates that institutions must ensure the implementation and further development of outsourcing management and corresponding control and monitoring processes. Ongoing documentation of outsourced activities and processes as well as coordination and review of risk management must also be ensured.
The services to be provided, auditing rights, powers to give instructions, and notice periods must be specified in a comprehensive outsourcing contract to formally ensure the continuity and quality of the outsourced processes. Furthermore, the contractual relationship must also include rules covering subcontracting, which is when the service provider in turn hires a subcontractor to perform the services. Particular attention is paid to the possible right to reserve approval and the obligation to provide information along the entire supply chain up to the institution.
Björn Greif
Senior Editor
Björn started his career as an editor at the IT news portal ZDNet in 2006. 10 years and exactly 12,693 articles later, he joined the German start-up Cliqz to campaign for more privacy and data protection on the web. It was then only a small step from data protection to IT security: Björn has been writing about the latest trends and developments in the world of cybersecurity at Myra since 2020.