BaFin - Navigation & Service

Topic Risk management IT risks at banks and insurance undertakings

Article from BaFin's 2017 annual report

Created by BaFin in 2017, BAIT communicates what BaFin expects of a proper IT organisation in banks in relation to the internal IT systems as well as the IT services the institutions purchase from third parties.1 BAIT is above all intended to raise the awareness of IT risk throughout the institutions – including with respect to their relationship with IT outsourcing providers.

BaFin is planning to publish the corresponding Supervisory Requirements for IT in Insurance Undertakings and Pension Funds (VAIT) in mid-2018. BaFin carried out an industry survey in the second half of the year 2017 in order to get an initial overview of how insurance undertakings and pension funds handle their exposure to cyber risk. This was aimed at identifying the typical strengths and weaknesses of the undertakings.

The survey was at the same time a way to let the industry know that BaFin considers IT risk, which includes cyber risk, material and will therefore examine this risk at the supervised undertakings even more closely in future.2

Cloud computing at insurance undertakings

A key issue that Insurance Supervision has been working on in great detail since 2017 is the use of cloud computing. As with any outsourcing arrangement, the insurance undertaking remains responsible for meeting all supervisory requirements and obligations in such a case. Furthermore, outsourcing must not restrict the undertaking's management and control options or BaFin's review and supervision rights. Banking Supervision is also giving close attention to the issue of cloud computing. Here, the same supervisory requirements apply with regard to outsourcing as is the case with insurance undertakings.

  1. 1 For details on BAIT, see chapter III 1.4.2.
  2. 2 For details on this survey, see chapter I 2.

Did you find this article helpful?

We appreciate your feedback

Your feedback helps us to continuously improve the website and to keep it up to date. If you have any questions and would like us to contact you, please use our contact form. Please send any disclosures about actual or suspected violations of supervisory provisions to our contact point for whistleblowers.

We appreciate your feedback

* Mandatory field

Publications on this topic

”Start get­ting ready for DO­RA now”

(BaFinJournal) Throughout Europe, companies in the financial sector are being called on to protect themselves more effectively against IT risk. Jan Kiefer from BaFin’s IT Supervision explains what this means for risk management.

“Now is the time to pre­pare”

(BaFinJournal) Many credit institutions are reporting very strong profits. But the risk of credit defaults is rising, warns Adam Ketessidis, head of BaFin’s Directorate for Risk Analysis, Macro-Prudential Supervision and Crisis Management.

The risks are on the rise

(BaFinJournal) Floods, forest fires and other natural catastrophes are expected to occur more frequently in future. And they could cause even greater losses. Can insurers bear the risks?

Article by Robert Ganz, Dr Marco Henkel, Jörg Müller, Max Schuppelius and Dr Filip Uzelac-Schüler, BaFin Insurance Supervision

Out­sourc­ing in the fi­nan­cial sec­tor: Greater trans­paren­cy means greater se­cu­ri­ty

(BaFinJournal) Companies within the financial sector are outsourcing more and more services to specialised providers. Although this has many advantages, outsourcing also makes the financial market more vulnerable. That is why it is necessary to report outsourcing to BaFin. The data submitted reveal how closely intertwined certain companies are with each other. By Dr Sibel Kocatepe, IT Supervision …

An­nounce­ment re­gard­ing Umwelt­Bank AG

On 26 February 2024, the Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht BaFin) appointed a special commissioner for UmweltBank. The special commissioner will monitor how the institution ensures that it has in place a proper business organisation.

All documents