Topic: Recht & Aufsicht
What is BAIT?
BAIT (Bankaufsichtliche Anforderungen an die IT) is a BaFin circular from 2017 (amended in 2021 and 2024) that specifies IT requirements for banks and financial services providers — complementing MaRisk AT 7.
BAIT covers topics such as IT strategy, IT governance, information risk management, identity and access management, IT projects and application development, IT operations, outsourcing and end-user computing (IDV).
BAIT implementation mandates require IT consultancies with a banking track record. Generalist IT firms frequently fail on the interpretation of the MaRisk AT 7 interface.
Related terms
- MaRiskMaRisk (Mindestanforderungen an das Risikomanagement) is a BaFin circular setting out the requirements for internal risk management at German banks and financial services providers — binding in substance since 2005, with regular amendments.
- BaFinBaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) is the German supervisory authority for banks, insurers, securities trading and payment services — based in Bonn and Frankfurt am Main, founded in 2002.
- DORADORA (Digital Operational Resilience Act) is an EU regulation that has applied to financial entities in the EU since January 2025. It governs digital operational resilience — IT risk management, incident reporting, penetration testing and third-party risk — and complements national frameworks such as MaRisk and BAIT.
Last updated: 2026-05-05