Back to lessons
Lesson 05

BAIT Explained

IT strategy, operations, outsourcing. What BAIT means in practice and how it sits next to the new AI rules.

What is BAIT?

BAIT stands for Bankaufsichtliche Anforderungen an die IT, the Banking Supervisory Requirements for IT. It is a BaFin circular issued in coordination with the Deutsche Bundesbank.

Where MaRisk sets the principle (in AT 7.2: the bank must manage IT risk), BAIT is the operational manual that tells you exactly what that looks like. If BaFin writes to a bank with IT findings, the letter will cite BAIT chapter and verse, not MaRisk AT 7.2.

BAIT was first published in 2017 and substantially updated in 2021 (cloud, information security, contingency) and 2024 (alignment with DORA). The 2024 version narrowed some passages where DORA now leads, but BAIT continues to govern the German-specific operational expectations BaFin examines.

Who has to follow BAIT

Every credit institution and financial services institution in Germany that is in scope of MaRisk. Same population: Sparkassen, Volksbanken, Landesbanken, commercial banks, investment firms. BAIT has three sister circulars for adjacent sectors:

All four share the same DNA with sector-specific nuances. Master BAIT and you can read the others in an afternoon.

The chapter structure

BAIT chapters follow the IT lifecycle. Each chapter has detailed operational expectations.

Chapter 1: IT strategy

Chapter 2: IT governance

Chapter 3: Information risk management

Chapter 4: Information security management

Chapter 5: Operational information security

Chapter 6: Identity and access management

Chapter 7: IT projects and application development

Chapter 8: IT operations

Chapter 9: Outsourcing of IT services and other third-party relationships

Chapter 10: IT contingency management

BAIT and cloud computing

The 2021 update added explicit treatment of cloud computing; the 2024 update preserved it. Cloud arrangements are a regular BAIT examination topic.

How BAIT treats AI

BAIT has no dedicated AI chapter. AI is examined through every chapter:

A BAIT examination of an AI system can touch every chapter. The bank's BAIT file on the AI has to answer all ten supervisory angles in a consistent narrative.

How BAIT interacts with the other frameworks

What to do next

This lesson is educational, not legal advice. Confirm with qualified counsel before relying on any classification for compliance submissions.
All lessonsTry the classifier
SchutzIQ — EU compliance platform