Governance

BAIT (Banking Supervisory Requirements for IT)

BaFin's regulatory framework specifying IT requirements for German banks. BAIT translates MaRisk into concrete IT security standards covering information security management, user access management, IT projects, application development, IT operations, and outsourcing.

BAIT (Bankaufsichtliche Anforderungen an die IT) is BaFin's supervisory framework that specifies how German banks must manage their IT infrastructure and security. First published in 2017 and updated in 2021, BAIT translates the broader MaRisk (Minimum Requirements for Risk Management) into actionable IT requirements.

BAIT covers nine core areas: IT strategy, IT governance, information security management, user access management, IT projects and application development, IT operations (including data management), outsourcing and other third-party services, IT business continuity management, and critical infrastructure. Each area contains specific requirements for documentation, processes, and controls.

With the implementation of DORA, BAIT requirements are being aligned with the new EU-wide framework. However, BAIT remains relevant as it contains Germany-specific requirements that may exceed DORA's baseline. Financial institutions must comply with both frameworks simultaneously, making an integrated compliance approach essential.

Learn More

Discover how Matproof can help you achieve BAIT (Banking Supervisory Requirements for IT) compliance.

View framework page

Automate compliance with Matproof

DORA, SOC 2, ISO 27001 — get audit-ready in weeks, not months.

Request a demo