KAIT
Capital Management Supervisory Requirements for IT (Germany)
Kapitalverwaltungsaufsichtliche Anforderungen an die IT
The KAIT were the Federal Financial Supervisory Authority (Germany) (BaFin) circular specifying IT-supervisory expectations specifically for capital management companies — the sector-specific counterpart to the Banking Supervisory Requirements for IT (Germany) (BAIT). They transferred principles on IT governance, information security and outsourcing to the fund industry. With the European Union (EU) regulation Digital Operational Resilience Act (DORA) they were repealed.
History & facts. The KAIT were part of the family of xAIT circulars with which Federal Financial Supervisory Authority (Germany) (BaFin) formulated uniform IT expectations across the financial sectors. To avoid double regulation with Digital Operational Resilience Act (DORA), BaFin repealed the KAIT with effect from the end of 16 January 2025; from 17 January 2025 the DORA requirements apply directly to the affected companies.
Outlook & recommendation. Even though the KAIT are formally repealed: their requirements are largely reflected in Digital Operational Resilience Act (DORA), and implemented processes remain usable. Capital management companies should mirror their existing implementation status against DORA via a gap analysis rather than starting from scratch — much is already in place, while other elements (such as the third-party information register) are new.