BaFin

Federal Financial Supervisory Authority (Germany)

Bundesanstalt für Finanzdienstleistungsaufsicht

BaFin is the German supervisory authority for banks, insurers, capital management and payment service providers, founded in 2002 with offices in Bonn and Frankfurt am Main. It oversees the stability and integrity of the financial sector and over the years issued the IT-supervisory circulars of the xAIT family (Banking Supervisory Requirements for IT (Germany) (BAIT), Insurance Supervisory Requirements for IT (Germany) (VAIT), Capital Management Supervisory Requirements for IT (Germany) (KAIT), Payment Services Supervisory Requirements for IT (Germany) (ZAIT)) for this purpose. With the European Union (EU) regulation Digital Operational Resilience Act (DORA) it is also the central national supervisor for digital operational resilience.

History & facts. BaFin was created in 2002 from the merger of the previously separate supervisory offices for banking, insurance and securities trading; it is under the Federal Ministry of Finance and is Germany's competent national authority within the European supervisory structure. In the banking area it works closely with the Deutsche Bundesbank. With the application of Digital Operational Resilience Act (DORA) it has repealed or set on a path to expiry the national xAIT circulars in order to avoid double regulation.

Contact & reporting. Main offices: Graurheindorfer Str. 108, 53117 Bonn (PO Box 1253, 53002 Bonn) and Marie-Curie-Str. 24-28, 60439 Frankfurt am Main. Phone +49 228 4108-0, fax +49 228 4108-1550, e-mail poststelle@bafin.de, website www.bafin.de. Digital Operational Resilience Act (DORA)-specific reporting and submission routes (for instance to the information register or for incident reporting) are governed by the BaFin and European Union (EU) procedures; the current state on bafin.de is authoritative.

Outlook & recommendation. For supervised institutions, Digital Operational Resilience Act (DORA) shifts the point of reference from national circulars to directly applicable European Union (EU) law — including new duties such as the information register for ICT third parties. The key is not to discard the existing processes aligned with xAIT but to match them specifically against the DORA requirements and add the genuine novelties.

BaFin — Federal Financial Supervisory Authority (Germany)