VAIT

Insurance Supervisory Requirements for IT (Germany)

Versicherungsaufsichtliche Anforderungen an die IT

The VAIT were the Federal Financial Supervisory Authority (Germany) (BaFin) circular specifying IT-supervisory expectations for insurance undertakings — the sector-specific counterpart to Banking Supervisory Requirements for IT (Germany) (BAIT) and Capital Management Supervisory Requirements for IT (Germany) (KAIT). They transferred principles on IT governance, information security, outsourcing and contingency management to the insurance sector. With the European Union (EU) regulation Digital Operational Resilience Act (DORA) they were repealed.

History & facts. The VAIT belonged to the family of xAIT circulars with which Federal Financial Supervisory Authority (Germany) (BaFin) formulated uniform IT expectations across the financial sectors. As institutional investors and custodians of large data holdings, insurers are an attractive target; the VAIT reflected this with requirements on information security and outsourcing governance. To avoid double regulation, BaFin repealed the VAIT with effect from the end of 16 January 2025.

Outlook & recommendation. Since 17 January 2025 the Digital Operational Resilience Act (DORA) requirements apply directly to the affected insurers. The substantive overlap is large, but DORA brings its own emphases — in particular the mandatory management of ICT third-party risk and the information register. Those who aligned their processes with the VAIT should check the status against DORA via a gap analysis and specifically add the new duties.

VAIT — Insurance Supervisory Requirements for IT (Germany)