Auslagerung Interne Revision (German-language service page)
The German-language counterpart of this service, for German-speaking stakeholders within your organization.
View serviceInternal Audit under Sec. 25a(1) No. 3 KWG and BT 2 MaRisk
S+P Compliance takes on Internal Audit – fully independent, with a risk-based audit plan and a clear procedure for the case of full outsourcing.
Institutions must maintain an independent Internal Audit function under Sec. 25a(1) No. 3 of the German Banking Act (Kreditwesengesetz, KWG) that reviews all activities and processes on a risk basis. Unlike other control functions, a strict rule applies here: Internal Audit may not be combined with other business areas or control functions of the institution. The basis for tasks, independence, and audit planning is BT 2 MaRisk.
This audit activity can be outsourced, responsibility for an effective internal control system cannot. Where Internal Audit is fully outsourced, BT 2.4 MaRisk requires management to appoint an audit officer who ensures Internal Audit is properly carried out. We set up the mandate so this structure is in place from day one.
Audit note: every audit engagement is version-controlled, time-stamped, and logged with a decision record. On request, auditors receive a structured trail of who identified which finding, when, and what action followed.
Outsourcing a control function means you must monitor the service provider and be able to evidence that monitoring. S+P Compliance provides audited evidence that your external auditor, your supervisor, and your own governance can use directly. It shortens your own audit procedures, it does not replace them: outsourcing shifts the performance of audits, not responsibility for an effective internal control system.
S+P Compliance’s internal control system has been audited under the German IDW standard for service organizations. The report describes control objectives, controls, and their effectiveness, and can be included in your own assessment of the outsourcing arrangement.
Outsourcing auditFor groups with a foreign parent company or an internationally operating group auditor, the equivalent report under the international standard is available. That removes any debate over whether a purely national standard is sufficient for group audit purposes.
InternationalThe quality management system is certified. Processes, responsibilities, document control, and corrective actions are defined and regularly audited – the basis for meeting agreed response times and reporting cycles.
Quality managementThe information security management system is certified. This matters because outsourcing Internal Audit means audit files, findings, and reports are processed outside your own organization, and this is a point supervisors regularly review.
Information securityS+P Compliance holds a confirmed ESG rating. This simplifies your vendor assessment process and allows you to include the service provider in your own sustainability reporting.
SustainabilityAudit reports and certificates are provided on request – including directly to your external auditor or your supervisory authority. This is anchored in the outsourcing agreement as an information and audit right.
On requestAn outsourcing arrangement only works if decision-making authority is set out in writing beforehand. We apply one fixed principle: S+P Compliance performs and documents, your institution decides on remediation.
Internal Audit may not be combined with other business areas or control functions of the institution (Sec. 25a(1) No. 3 KWG). Where Internal Audit is fully outsourced, management appoints an audit officer (BT 2.4 MaRisk). Outsourcing shifts the performance of audits, not responsibility for an effective internal control system.
Three developments hit Internal Audit at the same time – each on its own could be absorbed internally, together they add up.
The audit plan must cover all activities and processes of the institution at appropriate intervals and remain risk-based, aligned to the underlying risk classification. For a single internal function, covering this scope with the required depth is rarely sustainable in smaller and mid-sized institutions – particularly since short-notice special audits must remain available at all times, alongside the regular plan.
BT 2.1 and BT 2.3 MaRisk – audit mandate and planningUnlike other control functions, the law allows no combination here: Internal Audit may not be combined with other business areas or control functions of the institution, and audit staff must generally not take on tasks outside audit work. In smaller institutions, this strict separation is often difficult to maintain with the available staff.
Sec. 25a(1) No. 3 KWG – no combination permittedWith the 9th MaRisk amendment of 30 June 2026, BaFin has cautiously widened the scope for outsourcing arrangements without relaxing institutions‘ responsibility – and the role of Internal Audit in particular has been made more flexible. Institutions that document their audit organization cleanly now can use this scope, rather than reconstructing it after the fact.
30.06.2026 – 9th MaRisk amendment: more flexible Internal AuditThe following findings show up in audit reports on a regular basis. They describe typical patterns, not specific institutions.
Resignation or extended absence hit a function that must be continuously staffed. A short-term internal substitute quickly breaches the no-combination rule, because the person stepping in usually already holds another role in the institution.
The audit plan is updated annually, but the underlying risk classification is not reviewed on a regular basis. New business lines or processes only appear in the audit programme with a delay.
Audit staff temporarily take on tasks outside the audit function, without that exception being documented or time-limited. This is exactly what supervisors examine first.
Findings are documented, but the agreed deadline monitoring under BT 2.5 MaRisk does not happen systematically. Open deficiencies remain unnoticed until the next audit picks them up again.
When deficiencies surface or a special information need arises, Internal Audit must be able to review it on short notice. Where capacity is lacking, exactly the audit that is needed most urgently gets delayed.
Full outsourcing requires management to appoint an audit officer under BT 2.4 MaRisk who ensures Internal Audit is properly carried out. In practice, this appointment is often overlooked when the outsourcing agreement is drafted.
The scope is set out in the outsourcing agreement. You can transfer Internal Audit in full or engage S+P Compliance for specific topics alongside an existing internal audit function.
Full independence, with no combination with any other function.
Allocation: for full outsourcing, BT 2.4 MaRisk requires management to appoint an audit officer who oversees that the outsourced Internal Audit function is properly carried out. S+P Compliance supports the design of this role; the appointment itself is made by the institution. Outsourcing shifts the performance of audits, not responsibility for an effective internal control system.
A plan that shows the origin of every audit engagement in a concrete risk assessment.
Regular audits under the plan, and short-notice availability for special cases.
Reports that keep findings, recommendations, and responsibility clearly separated.
Tracking that only ends once remediation is documented as complete.
Allocation: S+P Compliance tracks findings and documents the implementation status. The decision on the specific remediation measure and its implementation rests with the affected business area or management.
An audit methodology that keeps pace with regulatory change.
An outsourcing arrangement does not become reliable through service delivery alone, but through its governance. We fix these four elements before the mandate starts.
Scope of services, reporting line, and the prohibition on combining Internal Audit with other functions are fixed in writing, so that independence remains evidenced.
Your institution keeps the ability to steer the mandate. Access, information, and audit rights are agreed for the institution, external auditors, and the supervisory authority.
Alongside the named audit team, an onboarded substitute is fixed by contract. Response times for special audits are part of the agreement, not an informal understanding.
A defined procedure exists for termination, transition, or bringing the function back in-house: data handover, transition documentation, and onboarding of a successor are described in advance.
The right model depends on size, the existing audit structure, and current audit priorities. Models can be switched over time.
S+P Compliance takes on Internal Audit in full. Management appoints an audit officer and retains the approval rights it cannot delegate.
Audit officer requiredInternal Audit remains in place, S+P Compliance covers specific topics or audit areas where internal expertise does not go deep enough.
SupplementFixed-term staffing during a vacancy or the build-out of a new audit function, combined with a structured handover to the internal successor.
Transition periodA single engagement for a specific special audit without an ongoing mandate, for example following identified deficiencies or a particular information need.
Single engagementTiming depends on how complete your risk inventory and existing audit plan already are.
Institution size, business model, existing audit structure, and open findings are captured. The result is a stocktake with clear priorities.
We assess risk areas, independence requirements, and interfaces, and present a proposal with a defined scope of services and reporting rhythm.
The outsourcing agreement is signed, management appoints an audit officer, and the first risk-based audit plan is approved.
Ongoing audit performance under the plan, interim reporting, an annual report to management, and systematic follow-up on findings.
Four processes determine, in the event of an audit, whether an outsourcing arrangement was set up cleanly. For each of them, we set out in writing who performs and documents, and who decides. This allocation is part of the outsourcing agreement and is not negotiated in day-to-day business.
The principle applies throughout: S+P Compliance performs and documents, your institution decides. Internal Audit may not be combined with other control functions – outsourcing shifts the performance of audits, not responsibility for an effective internal control system.
| Process | S+P Compliance performs and documents | Decision and responsibility at the institution | Legal reference |
|---|---|---|---|
| Audit plan | Assessment, risk classification, plan draft with prioritization | Approval of the plan and any significant adjustments by management | BT 2.3 MaRisk |
| Audit performance | Performance, documentation, assessment of the internal control system | Provision of information and access to documents | BT 2.1 MaRisk |
| Findings and deficiencies | Documentation, recommendation, deadline proposal, systematic follow-up | Decision on remediation and its implementation | BT 2.5 MaRisk |
| Full outsourcing | Audit performance and reporting on behalf of the institution | Appointment of an audit officer to ensure proper performance | BT 2.4 MaRisk |
In an initial conversation we clarify institution size, existing audit structure, and any open findings from your last audit. The outcome is an assessment of which engagement model fits and who could take on the audit officer role.
The audit team and substitute are contractually fixed, onboarded, and available at short notice for special audits.
ContinuityNo combination with other functions, no operational involvement – the separation is structural and contractually secured.
IndependenceFindings, recommendations, and deadlines are clearly documented, rather than reconstructed only at the next audit.
DocumentationScope of services and fees are contractually defined. Recruitment, onboarding, and training no longer appear as separate line items.
Cost predictabilityChanges such as the 9th MaRisk amendment of 30 June 2026 are continuously integrated into the audit plan and audit methodology.
CurrencyWho audits, who documents, and who decides is set out in writing. That reduces follow-up questions during external audits.
GovernanceThis service is aimed at institutions under Sec. 25a(1) No. 3 KWG that must maintain an independent Internal Audit function under BT 2 MaRisk.
Outsourcing Internal Audit can be combined with further control functions, to the extent their respective independence requirements allow. All mandates follow the same role logic: performance is external, responsibility stays with your institution.
The German-language counterpart of this service, for German-speaking stakeholders within your organization.
View serviceThe English-language MLRO mandate, for FIU filings, transaction monitoring, and suspicious activity reporting.
View serviceAnti-money laundering prevention under Sec. 6 and Sec. 7 GwG, with suspicious activity reporting and transaction monitoring.
View serviceGeneral compliance function under AT 4.4.2 MaRisk, with monitoring, advice, and management reporting.
View serviceA focused mandate for MaRisk-compliant implementation and monitoring, including legal inventory management.
View serviceSecurities trading compliance under Sec. 80 WpHG, with product governance and complaints handling.
View serviceInformation security officer function under BAIT and Art. 6(4) DORA, with organizational independence.
View serviceData protection organization under the GDPR, with a records of processing activities and audit-proof documentation.
View serviceSteering and control of all outsourcing arrangements, including the outsourcing register, risk analyses, and reporting.
View serviceTimely, technically validated XBRL filings for FINREP and COREP, without running your own reporting software.
View serviceOperational support for alert handling, case closure, and backlog reduction – available at short notice and scalable.
View serviceCustomer due diligence in day-to-day operations: onboarding, periodic refresh, and clearance of outstanding cases.
View serviceS+P Compliance provides a qualified audit team that develops the risk-based audit plan, performs regular and short-notice special audits, assesses the adequacy and effectiveness of the internal control system, and documents findings with concrete recommendations. This is complemented by an annual report, interim reporting, and systematic follow-up on remediation under BT 2.5 MaRisk. The exact scope is set out in the outsourcing agreement.
This applies to institutions under Sec. 25a(1) No. 3 KWG: credit institutions, cooperative banks, financial services institutions, payment and e-money institutions, capital management companies, crypto custodians, and FinTechs with a German KWG or ZAG licence. Outsourcing is most useful where the strict no-combination rule is difficult to maintain with the available staff, or where capacity for special audits is lacking.
Yes. Outsourcing shifts the performance of audits, not responsibility for an effective internal control system. Where Internal Audit is fully outsourced, management must appoint an audit officer under BT 2.4 MaRisk who ensures the function is properly carried out. Approval of the audit plan and decisions on remediation for identified findings remain tasks of the institution.
The audit function is run organizationally and procedurally separate from any other mandate. Individuals auditing on your behalf do not take on tasks outside audit work in your institution and are not involved in operational processes they themselves assess. This separation is fixed in the outsourcing agreement and secured through the direct reporting line to your management.
No. Unlike other control functions, Sec. 25a(1) No. 3 KWG allows no exception here: Internal Audit may not be combined with other business areas or control functions of the institution. If you would also like to outsource the compliance function, the Money Laundering Reporting Officer, or other control functions, we set up separate, organizationally distinct mandates for that purpose.
The mandate is grounded in Sec. 25a(1) No. 3 KWG and BT 2 MaRisk, which sets out tasks in BT 2.1, independence and functional separation in BT 2.2, audit planning in BT 2.3, requirements for full outsourcing including the appointment of an audit officer in BT 2.4, and follow-up on findings in BT 2.5. The 9th MaRisk amendment of 30 June 2026 has made the outsourcing rules for Internal Audit more flexible. This overview reflects the legal position as of September 2026.
An outsourced Internal Audit function works when two things come together: a risk-based audit plan that follows your business model, and a role allocation that can be evidenced in an audit. S+P Compliance sets up both together with you – audit performance is transferred, responsibility for an effective internal control system stays with your institution.


Achim Schulz verantwortet die S+P Compliance Services. Da S+P als Dienstleister für regulierte Institute fortlaufend von Wirtschaftsprüfern und Aufsichtsbehörden geprüft wird, ist die Prüfungsexpertise seines Teams immer auf dem neuesten Stand. Ihr Vorteil: Er weiß aus der täglichen Praxis exakt, welche Nachweise und Kontrollen in aktuellen Audits zwingend gefordert werden. Diese tagesaktuelle Expertise fließt direkt in Ihre Auslagerung ein. Sie profitieren von zertifizierten Prozessen (IDW PS 951, ISO), die jedem Audit durch die BaFin oder Ihren Abschlussprüfer absolut sicher standhalten.
LinkedIn-Profil → · Redaktion & Experten → · S+P Compliance Services →Wir verwenden Cookies und ähnliche Technologien, um Ihre Erfahrung auf unserer Website zu verbessern. Weitere Informationen in unserer Datenschutzerklärung.