ZAIT

Payment Services Supervisory Requirements for IT (Germany)

Zahlungsdiensteaufsichtliche Anforderungen an die IT

The ZAIT were the Federal Financial Supervisory Authority (Germany) (BaFin) circular specifying IT-supervisory expectations for payment service providers and e-money institutions — the youngest member of the xAIT family. They transferred the established principles on IT security and outsourcing to a particularly dynamic, technology-driven sector. With the European Union (EU) regulation Digital Operational Resilience Act (DORA) they were repealed.

History & facts. The payment-services sector is characterised by many young, highly connected providers whose core business depends directly on the availability and integrity of their IT. The ZAIT formulated concrete supervisory expectations for this. To avoid double regulation with Digital Operational Resilience Act (DORA), Federal Financial Supervisory Authority (Germany) (BaFin) repealed the ZAIT with effect from the end of 16 January 2025; since then the DORA requirements apply directly.

Outlook & recommendation. For technology-driven payment service providers in particular, Digital Operational Resilience Act (DORA) is more than a change of label: the mandatory management of ICT third-party risk hits a sector that relies intensively on cloud and platform services. Governing and monitoring these third-party dependencies — including defensible detection and response — thus becomes a permanent task rather than a one-off implementation.

ZAIT — Payment Services Supervisory Requirements for IT (Germany)