Germany

DE · DEU · Europe · Last verified 22 Sep 2026

5 regulators · 6 instruments · 6 obligations · 1 upcoming deadline

Germany — hero image

Circular 2017

Supervisory Requirements for IT in Financial Institutions(BAIT)

Bankaufsichtliche Anforderungen an die IT

Issued by Federal Financial Supervisory Authority

Effective: 6 Nov 2017

Last amended: 17 Jan 2025

Plain-English summary

BAIT is a binding administrative circular (Rundschreiben) of the German financial supervisory authority BaFin, which is intended to facilitate the translation of the legal regulatory banking framework into technical and organizational standards. It was originally introduced in 2017 and is known as Bankaufsichtliche Anforderungen an die IT. BAIT is regarded as the main technical module that works in conjunction with the general MaRisk framework, specifying particular requirements for information security and IT systems. In its present phased sunset period, BAIT acts as a transitional tool toward the supreme DORA regulation of the EU. Major actors of the financial system have been exempted from BAIT since 17 January 2025 due to their necessity to comply only with DORA, while other financial institutions operating in Germany will be obligated to follow the January 2025 version of BAIT until its total repeal on 31 December 2026.

Who it applies to

Banking

Topics

Cybersecurity & IT Risk

Official source

Latest news

No related news yet. We publish updates as regulators act.

Browse all newsSubscribe for updates