Skip to main content
MaRisk · BAIT8 Jun 2026 · 5 min read

MaRisk, BAIT and AI: outsourcing and model governance in German banking

MaRisk and BAIT are the BaFin circulars that shape risk management and IT in German banks. They do not name AI, but they govern its use through outsourcing and IT-governance requirements — increasingly in interplay with DORA.

What MaRisk and BAIT govern

MaRisk (Minimum Requirements for Risk Management) is a binding BaFin circular that gives concrete form to the organisational duties of Section 25a of the German Banking Act (KWG) and translates them into auditable requirements for governance, steering and control. It is modular: the General Section (AT modules) holds the core requirements, including the outsourcing rules in AT 9.

BAIT (Supervisory Requirements for IT in Financial Institutions) refined these principles for IT — covering IT strategy, information security, access management and the procurement of IT services. Both circulars are principles-based and proportionate, so institutions can shape solutions in line with their size and risk profile.

AT 9: outsourcing requirements

AT 9 requires a risk analysis before any outsourcing to determine whether it is a material outsourcing. Material outsourcings carry stricter duties: written contracts with information, audit and instruction rights, ongoing monitoring of service quality, and explicitly defined exit management that safeguards continuity of the activity if the provider fails. The requirements also apply where the provider sub-outsources.

  • Risk analysis and materiality classification before contracting, then kept current.
  • Full documentation of all outsourcings (an outsourcing register is common practice).
  • Robust exit management with fallback options for provider failure.
  • Ultimate management responsibility remains and cannot be outsourced.

Where AI model governance fits

Neither MaRisk nor BAIT names AI explicitly. Its use is nonetheless captured by existing principles: an externally sourced model or AI service can be a material outsourcing under AT 9, while IT-governance, information-security and data-quality requirements apply to the development and operation of in-house models. Where an institution consumes a model as a cloud or SaaS service, it must evidence risk analysis, contractual rights and exit options accordingly.

In practice this means demonstrable model governance: documented purpose, clear ownership, validation and monitoring, human oversight for material decisions, and an audit trail that withstands supervisory and internal-audit scrutiny. These building blocks flow from the general requirements, not from a dedicated AI rule.

The interplay with DORA

The EU regulation DORA (Regulation (EU) 2022/2554 of 14 December 2022) has applied directly since 17 January 2025 and harmonises ICT risk management across Europe. For IT and AI service providers, DORA obligations — information register, contractual content, testing and exit strategies — therefore apply directly. The IT-specific BAIT is being superseded for DORA-obliged institutions and is fully phased out by the end of 2026; MaRisk and Section 25b KWG remain the basis for outsourcing management.

On 30 June 2026, BaFin published the ninth MaRisk revision: shorter, more principles-based and aligned more closely with the European framework to avoid duplicate regulation. Institutions should cleanly delineate ICT and non-ICT outsourcing and place their AI initiatives within both regimes.

Key takeaway

Treat every externally sourced AI service as a potentially material outsourcing — with risk analysis, documented model governance and robust exit management — and simultaneously place it within the DORA framework.

Book a demo

Turn the regulation into a running system.

30 minutes, scoped to your frameworks and integrations. You leave with a concrete plan — not a sales loop.