Zum Hauptinhalt springen

Internal Audit under Sec. 25a(1) No. 3 KWG and BT 2 MaRisk

Outsourcing Internal Audit

S+P Compliance takes on Internal Audit – fully independent, with a risk-based audit plan and a clear procedure for the case of full outsourcing.

Institutions must maintain an independent Internal Audit function under Sec. 25a(1) No. 3 of the German Banking Act (Kreditwesengesetz, KWG) that reviews all activities and processes on a risk basis. Unlike other control functions, a strict rule applies here: Internal Audit may not be combined with other business areas or control functions of the institution. The basis for tasks, independence, and audit planning is BT 2 MaRisk.

This audit activity can be outsourced, responsibility for an effective internal control system cannot. Where Internal Audit is fully outsourced, BT 2.4 MaRisk requires management to appoint an audit officer who ensures Internal Audit is properly carried out. We set up the mandate so this structure is in place from day one.

  • Full organizational and procedural independence, with no combination with any other function.
  • Risk-based, annually updated audit plan with short-notice capacity for special audits.
  • Audit-proof reports with recommendations and systematic follow-up under BT 2.5 MaRisk.
  • Support in appointing an audit officer, as BT 2.4 MaRisk requires for full outsourcing.

Legal basis and audit evidence

  • Sec. 25a(1) No. 3 KWG
  • AT 4.4.3 MaRisk
  • BT 2 MaRisk
  • BT 2.4 MaRisk
  • BT 2.5 MaRisk

Audit note: every audit engagement is version-controlled, time-stamped, and logged with a decision record. On request, auditors receive a structured trail of who identified which finding, when, and what action followed.

Outsourcing a control function means you must monitor the service provider and be able to evidence that monitoring. S+P Compliance provides audited evidence that your external auditor, your supervisor, and your own governance can use directly. It shortens your own audit procedures, it does not replace them: outsourcing shifts the performance of audits, not responsibility for an effective internal control system.

IDW PS 951

S+P Compliance’s internal control system has been audited under the German IDW standard for service organizations. The report describes control objectives, controls, and their effectiveness, and can be included in your own assessment of the outsourcing arrangement.

Outsourcing audit

ISAE 3402

For groups with a foreign parent company or an internationally operating group auditor, the equivalent report under the international standard is available. That removes any debate over whether a purely national standard is sufficient for group audit purposes.

International

ISO 9001

The quality management system is certified. Processes, responsibilities, document control, and corrective actions are defined and regularly audited – the basis for meeting agreed response times and reporting cycles.

Quality management

ISO 27001

The information security management system is certified. This matters because outsourcing Internal Audit means audit files, findings, and reports are processed outside your own organization, and this is a point supervisors regularly review.

Information security

ESG rating

S+P Compliance holds a confirmed ESG rating. This simplifies your vendor assessment process and allows you to include the service provider in your own sustainability reporting.

Sustainability

Provision of documents

Audit reports and certificates are provided on request – including directly to your external auditor or your supervisory authority. This is anchored in the outsourcing agreement as an information and audit right.

On request

What is outsourced – and what stays with your institution

An outsourcing arrangement only works if decision-making authority is set out in writing beforehand. We apply one fixed principle: S+P Compliance performs and documents, your institution decides on remediation.

S+P Compliance performs and documents

  • Development of the risk-based, annually updated audit plan (draft)
  • Performance of independent regular audits and short-notice special audits
  • Assessment of the adequacy and effectiveness of the internal control system
  • Documentation of audit findings with concrete recommendations
  • Systematic follow-up on remediation under BT 2.5 MaRisk

Your institution decides and remains responsible

  • Approval of the audit plan and any significant adjustments by management
  • Appointment of an audit officer for full outsourcing (BT 2.4 MaRisk)
  • Decision on remediation for identified findings and their implementation
  • Approval of deadlines for remediation
  • Ultimate responsibility for an adequate internal control system

Internal Audit may not be combined with other business areas or control functions of the institution (Sec. 25a(1) No. 3 KWG). Where Internal Audit is fully outsourced, management appoints an audit officer (BT 2.4 MaRisk). Outsourcing shifts the performance of audits, not responsibility for an effective internal control system.

Why institutions outsource this function

Three developments hit Internal Audit at the same time – each on its own could be absorbed internally, together they add up.

  1. An audit mandate that covers the entire organization

    The audit plan must cover all activities and processes of the institution at appropriate intervals and remain risk-based, aligned to the underlying risk classification. For a single internal function, covering this scope with the required depth is rarely sustainable in smaller and mid-sized institutions – particularly since short-notice special audits must remain available at all times, alongside the regular plan.

    BT 2.1 and BT 2.3 MaRisk – audit mandate and planning
  2. Independence without exception

    Unlike other control functions, the law allows no combination here: Internal Audit may not be combined with other business areas or control functions of the institution, and audit staff must generally not take on tasks outside audit work. In smaller institutions, this strict separation is often difficult to maintain with the available staff.

    Sec. 25a(1) No. 3 KWG – no combination permitted
  3. A framework that keeps shifting

    With the 9th MaRisk amendment of 30 June 2026, BaFin has cautiously widened the scope for outsourcing arrangements without relaxing institutions‘ responsibility – and the role of Internal Audit in particular has been made more flexible. Institutions that document their audit organization cleanly now can use this scope, rather than reconstructing it after the fact.

    30.06.2026 – 9th MaRisk amendment: more flexible Internal Audit

Six points that recur in practice

The following findings show up in audit reports on a regular basis. They describe typical patterns, not specific institutions.

Vacancy and independence

Resignation or extended absence hit a function that must be continuously staffed. A short-term internal substitute quickly breaches the no-combination rule, because the person stepping in usually already holds another role in the institution.

Audit plan not risk-based

The audit plan is updated annually, but the underlying risk classification is not reviewed on a regular basis. New business lines or processes only appear in the audit programme with a delay.

Functional separation undocumented

Audit staff temporarily take on tasks outside the audit function, without that exception being documented or time-limited. This is exactly what supervisors examine first.

Follow-up on remediation lapses

Findings are documented, but the agreed deadline monitoring under BT 2.5 MaRisk does not happen systematically. Open deficiencies remain unnoticed until the next audit picks them up again.

Special audits not available at short notice

When deficiencies surface or a special information need arises, Internal Audit must be able to review it on short notice. Where capacity is lacking, exactly the audit that is needed most urgently gets delayed.

No audit officer appointed

Full outsourcing requires management to appoint an audit officer under BT 2.4 MaRisk who ensures Internal Audit is properly carried out. In practice, this appointment is often overlooked when the outsourcing agreement is drafted.

Scope of services

The scope is set out in the outsourcing agreement. You can transfer Internal Audit in full or engage S+P Compliance for specific topics alongside an existing internal audit function.

Mandate as outsourced Internal Audit

Full independence, with no combination with any other function.

  • Appointment of a qualified audit team with evidence of professional qualification
  • Full organizational and procedural independence under Sec. 25a(1) No. 3 KWG
  • No combination with other control functions or business areas
  • Direct reporting line to management
  • Support in appointing an internal audit officer
  • Fixed substitution arrangement for peak capacity and special audits
  • Coordination of interfaces with the compliance function and the Money Laundering Reporting Officer
  • Handover documentation at the start and end of the mandate

Allocation: for full outsourcing, BT 2.4 MaRisk requires management to appoint an audit officer who oversees that the outsourced Internal Audit function is properly carried out. S+P Compliance supports the design of this role; the appointment itself is made by the institution. Outsourcing shifts the performance of audits, not responsibility for an effective internal control system.

Risk-based audit plan

A plan that shows the origin of every audit engagement in a concrete risk assessment.

  • Assessment of all activities, processes, and risk areas of the institution
  • Regular risk classification as the basis for audit intensity
  • Development of a multi-year, annually updated audit plan
  • Risk-based prioritization of audit areas
  • Consideration of expected changes in risk potential
  • Coordination of the plan with management and, where applicable, the supervisory body
  • Preparation of the plan for approval by management
  • Documentation of the planning methodology for audit readiness

Audit performance

Regular audits under the plan, and short-notice availability for special cases.

  • Performance of risk-based regular audits under the audit plan
  • Short-notice availability for special audits arising from deficiencies or specific information needs
  • Objective, independent audit work without operational involvement
  • Assessment of the adequacy and effectiveness of the internal control system
  • Use of risk-based audit methods and techniques
  • Documentation of audit steps and supporting evidence
  • Coordination with external auditors to avoid duplicate audit work
  • Compliance with recognized auditing standards

Reporting and communication

Reports that keep findings, recommendations, and responsibility clearly separated.

  • Preparation of clear, audit-proof reports with concrete recommendations
  • Annual report of Internal Audit to management
  • Interim reporting on open audits and deadlines
  • Immediate communication of significant findings to management
  • Preparation of communication with BaFin and other supervisory authorities
  • Reporting to the supervisory body, where provided for
  • Preparation of documents for external audits
  • Traceable documentation of the reporting history

Follow-up and remediation tracking

Tracking that only ends once remediation is documented as complete.

  • Systematic follow-up on all audit findings through to closure
  • Monitoring of agreed deadlines for remediation
  • Escalation where implementation is delayed or does not occur
  • Re-review of implemented measures
  • Analysis of recurring findings for structural weaknesses
  • Coordination with the affected business area on implementation
  • Documentation of the entire follow-up process
  • Integration of results into the annual reporting

Allocation: S+P Compliance tracks findings and documents the implementation status. The decision on the specific remediation measure and its implementation rests with the affected business area or management.

Quality assurance and further development

An audit methodology that keeps pace with regulatory change.

  • Regular review of planning, methods, and quality of audits
  • Further development of audit methodology in line with new regulatory requirements
  • Alignment with changes such as the 9th MaRisk amendment of 30 June 2026
  • Internal quality assurance of audit work
  • Training of the audit team on current auditing standards
  • Benchmarking of audit methodology against recognized standards
  • Documentation of methodology development for external quality reviews
  • Coordination with management on strategic audit priorities

Outsourcing agreement and ongoing governance

An outsourcing arrangement does not become reliable through service delivery alone, but through its governance. We fix these four elements before the mandate starts.

Contract and independence

Scope of services, reporting line, and the prohibition on combining Internal Audit with other functions are fixed in writing, so that independence remains evidenced.

Instruction and information rights

Your institution keeps the ability to steer the mandate. Access, information, and audit rights are agreed for the institution, external auditors, and the supervisory authority.

Deputy and availability

Alongside the named audit team, an onboarded substitute is fixed by contract. Response times for special audits are part of the agreement, not an informal understanding.

Exit and reintegration

A defined procedure exists for termination, transition, or bringing the function back in-house: data handover, transition documentation, and onboarding of a successor are described in advance.

Four engagement models

The right model depends on size, the existing audit structure, and current audit priorities. Models can be switched over time.

Full mandate

S+P Compliance takes on Internal Audit in full. Management appoints an audit officer and retains the approval rights it cannot delegate.

Audit officer required

Supplementary audits

Internal Audit remains in place, S+P Compliance covers specific topics or audit areas where internal expertise does not go deep enough.

Supplement

Interim

Fixed-term staffing during a vacancy or the build-out of a new audit function, combined with a structured handover to the internal successor.

Transition period

Special audits

A single engagement for a specific special audit without an ongoing mandate, for example following identified deficiencies or a particular information need.

Single engagement

Four steps to an outsourced audit function

Timing depends on how complete your risk inventory and existing audit plan already are.

1

Clarify requirements

Institution size, business model, existing audit structure, and open findings are captured. The result is a stocktake with clear priorities.

2

Audit analysis and proposal

We assess risk areas, independence requirements, and interfaces, and present a proposal with a defined scope of services and reporting rhythm.

3

Agreement, audit officer, audit plan

The outsourcing agreement is signed, management appoints an audit officer, and the first risk-based audit plan is approved.

4

Audit, report, follow-up

Ongoing audit performance under the plan, interim reporting, an annual report to management, and systematic follow-up on findings.

Role allocation for liability-relevant decisions

Four processes determine, in the event of an audit, whether an outsourcing arrangement was set up cleanly. For each of them, we set out in writing who performs and documents, and who decides. This allocation is part of the outsourcing agreement and is not negotiated in day-to-day business.

The principle applies throughout: S+P Compliance performs and documents, your institution decides. Internal Audit may not be combined with other control functions – outsourcing shifts the performance of audits, not responsibility for an effective internal control system.

Process S+P Compliance performs and documents Decision and responsibility at the institution Legal reference
Audit plan Assessment, risk classification, plan draft with prioritization Approval of the plan and any significant adjustments by management BT 2.3 MaRisk
Audit performance Performance, documentation, assessment of the internal control system Provision of information and access to documents BT 2.1 MaRisk
Findings and deficiencies Documentation, recommendation, deadline proposal, systematic follow-up Decision on remediation and its implementation BT 2.5 MaRisk
Full outsourcing Audit performance and reporting on behalf of the institution Appointment of an audit officer to ensure proper performance BT 2.4 MaRisk

Is outsourcing the right fit for your setup?

In an initial conversation we clarify institution size, existing audit structure, and any open findings from your last audit. The outcome is an assessment of which engagement model fits and who could take on the audit officer role.

Request initial conversationCompare engagement models

What changes for your institution

The function is continuously staffed

The audit team and substitute are contractually fixed, onboarded, and available at short notice for special audits.

Continuity

Independence without compromise

No combination with other functions, no operational involvement – the separation is structural and contractually secured.

Independence

Audit-proof reports

Findings, recommendations, and deadlines are clearly documented, rather than reconstructed only at the next audit.

Documentation

Predictable cost

Scope of services and fees are contractually defined. Recruitment, onboarding, and training no longer appear as separate line items.

Cost predictability

Current audit methodology

Changes such as the 9th MaRisk amendment of 30 June 2026 are continuously integrated into the audit plan and audit methodology.

Currency

Clear roles

Who audits, who documents, and who decides is set out in writing. That reduces follow-up questions during external audits.

Governance

Who this service is for

This service is aimed at institutions under Sec. 25a(1) No. 3 KWG that must maintain an independent Internal Audit function under BT 2 MaRisk.

  • Credit institutions
  • Cooperative banks
  • Financial services institutions
  • Payment institutions
  • E-money institutions
  • Capital management companies
  • Crypto custodians and crypto service providers
  • FinTechs with a German KWG or ZAG licence
  • Branches of foreign institutions

Further outsourcing services from S+P Compliance

Outsourcing Internal Audit can be combined with further control functions, to the extent their respective independence requirements allow. All mandates follow the same role logic: performance is external, responsibility stays with your institution.

Control function

Outsourcing Compliance Officer

General compliance function under AT 4.4.2 MaRisk, with monitoring, advice, and management reporting.

View service
Data protection

Outsourcing Data Protection Officer

Data protection organization under the GDPR, with a records of processing activities and audit-proof documentation.

View service
Outsourcing governance

Central Outsourcing Management

Steering and control of all outsourcing arrangements, including the outsourcing register, risk analyses, and reporting.

View service
Operational delivery

AML Operations

Operational support for alert handling, case closure, and backlog reduction – available at short notice and scalable.

View service
Operational delivery

KYC Operations

Customer due diligence in day-to-day operations: onboarding, periodic refresh, and clearance of outstanding cases.

View service

Frequently asked questions about outsourcing Internal Audit

What specific tasks does S+P take over as the outsourced Internal Audit function?

S+P Compliance provides a qualified audit team that develops the risk-based audit plan, performs regular and short-notice special audits, assesses the adequacy and effectiveness of the internal control system, and documents findings with concrete recommendations. This is complemented by an annual report, interim reporting, and systematic follow-up on remediation under BT 2.5 MaRisk. The exact scope is set out in the outsourcing agreement.

Which companies benefit from this service?

This applies to institutions under Sec. 25a(1) No. 3 KWG: credit institutions, cooperative banks, financial services institutions, payment and e-money institutions, capital management companies, crypto custodians, and FinTechs with a German KWG or ZAG licence. Outsourcing is most useful where the strict no-combination rule is difficult to maintain with the available staff, or where capacity for special audits is lacking.

Does the institution retain ultimate responsibility for an effective internal control system?

Yes. Outsourcing shifts the performance of audits, not responsibility for an effective internal control system. Where Internal Audit is fully outsourced, management must appoint an audit officer under BT 2.4 MaRisk who ensures the function is properly carried out. Approval of the audit plan and decisions on remediation for identified findings remain tasks of the institution.

How does S+P ensure independence and audit-readiness?

The audit function is run organizationally and procedurally separate from any other mandate. Individuals auditing on your behalf do not take on tasks outside audit work in your institution and are not involved in operational processes they themselves assess. This separation is fixed in the outsourcing agreement and secured through the direct reporting line to your management.

Can Internal Audit be combined with other functions?

No. Unlike other control functions, Sec. 25a(1) No. 3 KWG allows no exception here: Internal Audit may not be combined with other business areas or control functions of the institution. If you would also like to outsource the compliance function, the Money Laundering Reporting Officer, or other control functions, we set up separate, organizationally distinct mandates for that purpose.

Which legal framework applies to this mandate?

The mandate is grounded in Sec. 25a(1) No. 3 KWG and BT 2 MaRisk, which sets out tasks in BT 2.1, independence and functional separation in BT 2.2, audit planning in BT 2.3, requirements for full outsourcing including the appointment of an audit officer in BT 2.4, and follow-up on findings in BT 2.5. The 9th MaRisk amendment of 30 June 2026 has made the outsourcing rules for Internal Audit more flexible. This overview reflects the legal position as of September 2026.

Outsourcing with a clear separation of roles

An outsourced Internal Audit function works when two things come together: a risk-based audit plan that follows your business model, and a role allocation that can be evidenced in an audit. S+P Compliance sets up both together with you – audit performance is transferred, responsibility for an effective internal control system stays with your institution.

Solution for Outsourcing Internal Audit
Achim Schulz
Ihr Ansprechpartner

Achim Schulz

Geschäftsführer S+P Compliance

Achim Schulz verantwortet die S+P Compliance Services. Da S+P als Dienstleister für regulierte Institute fortlaufend von Wirtschaftsprüfern und Aufsichtsbehörden geprüft wird, ist die Prüfungsexpertise seines Teams immer auf dem neuesten Stand. Ihr Vorteil: Er weiß aus der täglichen Praxis exakt, welche Nachweise und Kontrollen in aktuellen Audits zwingend gefordert werden. Diese tagesaktuelle Expertise fließt direkt in Ihre Auslagerung ein. Sie profitieren von zertifizierten Prozessen (IDW PS 951, ISO), die jedem Audit durch die BaFin oder Ihren Abschlussprüfer absolut sicher standhalten.

LinkedIn-Profil → · Redaktion & Experten → · S+P Compliance Services →