BAIT

Banking Supervisory Requirements for IT (Germany)

Bankaufsichtliche Anforderungen an die IT

The BAIT are a Federal Financial Supervisory Authority (Germany) (BaFin) circular that, on the basis of § 25a of the German Banking Act (KWG), specifies the supervisory expectations for the IT organisation and information security of banks. For years they were the authoritative national benchmark for IT security in the banking sector. With the European Union (EU) regulation Digital Operational Resilience Act (DORA) they are being phased out step by step.

History & facts. The BAIT (originally Federal Financial Supervisory Authority (Germany) (BaFin) Circular 10/2017) translated abstract legal requirements into auditable expectations for IT strategy, governance, access management, outsourcing and information security. With the application of Digital Operational Resilience Act (DORA) from 17 January 2025, their scope was reduced: institutions that must operate ICT risk management under DORA no longer fall under the BAIT, and the chapter on payment-service users was dropped.

Outlook & recommendation. Full repeal of the BAIT is scheduled for the end of 31 December 2026, staggered by institutions' scope and flanked by the Financial Market Digitalisation Act. Even as the BAIT formally expire: many of their requirements have been absorbed into Digital Operational Resilience Act (DORA) and remain relevant as established practice. Those who aligned their processes with BAIT have a good starting basis for DORA — a gap analysis reveals the remaining shortfalls.

BAIT — Banking Supervisory Requirements for IT (Germany)