Circular 2017
Supervisory Requirements for IT in Financial Institutions(BAIT)
Bankaufsichtliche Anforderungen an die IT
Issued by Federal Financial Supervisory Authority
Effective: 6 Nov 2017
Last amended: 17 Jan 2025
Plain-English summary
BAIT is a binding administrative circular (Rundschreiben) of the German financial supervisory authority BaFin, which is intended to facilitate the translation of the legal regulatory banking framework into technical and organizational standards. It was originally introduced in 2017 and is known as Bankaufsichtliche Anforderungen an die IT. BAIT is regarded as the main technical module that works in conjunction with the general MaRisk framework, specifying particular requirements for information security and IT systems. In its present phased sunset period, BAIT acts as a transitional tool toward the supreme DORA regulation of the EU. Major actors of the financial system have been exempted from BAIT since 17 January 2025 due to their necessity to comply only with DORA, while other financial institutions operating in Germany will be obligated to follow the January 2025 version of BAIT until its total repeal on 31 December 2026.
Who it applies to
Banking
Topics
Cybersecurity & IT Risk
Latest news
No related news yet. We publish updates as regulators act.