BAIT: BaFin's IT requirements and the move to DORA
The BAIT are BaFin's supervisory requirements for IT in banks, Circular 10/2017 (BA). DORA has taken over most of their ground, and the circular will be repealed completely when 2026 ends. Until then it applies to the institutions that do not yet fall under DORA's rules on ICT risk management.
What the BAIT cover
The BAIT rest on section 25a(1) of the German Banking Act for IT resource management, IT risk management and IT security management, and on section 25b for outsourcing, as the Deutsche Bundesbank explains. The current version is dated December 16, 2024. That revision removed chapter 11 on relationships with payment service users.
Since 2017 the BAIT have been the document that IT auditors, information security officers and external auditors checked a German bank against. They interpret MaRisk for IT, and the two circulars were read together: MaRisk for the organization of the bank, the BAIT for its systems, access rights, IT projects and IT operations.
From the BAIT to DORA
DORA has applied to banks, insurers, payment firms and investment firms since January 17, 2025. To avoid double regulation, BaFin repealed the sister circulars for payment institutions, insurers and asset managers, the ZAIT, VAIT and KAIT, and took every institution that has to apply DORA's ICT risk management framework, Articles 5 to 15 or the simplified framework in Article 16, out of the BAIT.
The Financial Market Digitalization Act, FinmadiG, brought more institutions under DORA: promotional banks from January 17, 2025 and financial services institutions under the KWG from January 1, 2027. According to Dr. Datenschutz, leasing companies are one example of firms that stay on the BAIT until then. On December 31, 2026 the BAIT expire.
What the switch means for IT and risk teams
Much of the content carries over, since DORA also asks for an ICT risk management framework, information security, access control, change and project management, backup and recovery. The differences are in the detail. DORA brings binding incident reporting to the supervisor, a register of information on all ICT contracts, resilience testing up to threat-led penetration tests and direct oversight of critical ICT providers.
For a firm that moves on January 1, 2027, the work is a mapping: every BAIT requirement against the DORA article and the technical standard that replaces it, with the gaps listed and owned. The incident reporting duty and the register are the parts with no BAIT predecessor.
Upcoming events on risk and compliance
Is the BAIT still valid?
Yes, for a shrinking group and for a limited time. The BAIT in the version of December 16, 2024 apply to KWG institutions that are not subject to DORA's ICT risk management rules, and they will be repealed completely with the end of December 31, 2026.
What happened to the VAIT, KAIT and ZAIT?
BaFin repealed all three when DORA took effect: the KAIT for asset managers, the VAIT for insurers and the ZAIT for payment and e-money institutions. Those sectors fall under DORA directly, so a second, German set of IT rules would have duplicated it.
Does MaRisk still contain IT requirements?
Yes, at a general level. The current MaRisk requires in AT 7.2 that the technical and organizational equipment matches the business and risk situation and that processes secure the quality of risk data, and AT 7.3 sets the emergency management. ICT services under DORA's third-party rules are outside the outsourcing module AT 9.
BAIT, DORA and Finance Loop
Finance Loop brings together the IT risk managers, information security officers and IT auditors at German banks who move their controls from the BAIT to DORA. Finance Loop announced KI Exchange 2026 in Hamburg, a conference whose program listed DORA compliance, and its DORA training page sets out what the regulation asks of staff and management.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.