BAIT gap analysis for German banking: what the framework audits and what it misses

Key takeaways
BAIT audits are documentation-heavy by design: BaFin examiners spend disproportionate time on IT strategy documents, information security concepts, and outsourcing registers — controls that are easy to produce and do not require the underlying security program to be functional.
Outsourcing accountability under BAIT stays with the regulated institution regardless of which IT service provider handles operations. German savings banks and cooperative banks using Atruvia or Finanz Informatik remain independently accountable for monitoring those relationships.
The gap between BAIT documentation compliance and actual security posture is widest in access management: institutions produce clean privileged access documentation for auditors while running service accounts and legacy API credentials that predate their current governance program.
DORA does not replace BAIT for German institutions — it adds to it. Institutions subject to both frameworks must reconcile differences in ICT incident reporting timelines and third-party register requirements, because the two obligations run in parallel.
BaFin examiners increasingly request evidence of continuous outsourcing monitoring — access logs, configuration change records, incident escalation trails — not just the contractual obligations that required monitoring to happen.
TL;DR
BAIT is a documentation framework that has accumulated real teeth. The original version from 2017 was governable by a prepared compliance team with good templates. The 2021 revision added outsourcing controls and information security requirements that require operational evidence, not just policy documents. The institutions that struggle with BAIT examinations are not the ones with bad security programs — they are the ones with good security programs and weak evidence trails. BaFin does not care what you do if you cannot show what you did.
The examination that found nothing wrong with the documentation
A German regional bank with approximately 800 employees completed a BaFin BAIT examination in late 2023. The IT strategy was current, board-approved, and well-structured. The information security concept ran to 140 pages. The outsourcing register was comprehensive. The examination passed without material findings. Four months later, Vulnox was engaged for a separate digital footprint assessment. Within two weeks, the team had identified three internet-exposed subdomains belonging to the bank's primary IT service provider that resolved to management interfaces with default authentication. The bank had a contractual right to audit the service provider. The service provider was in the outsourcing register. There was no evidence the bank had ever tested whether the contractual security obligations were being honored.
The examination validated the documentation of the outsourcing relationship. It had no mechanism to validate the security posture of the entity being outsourced to.
How BAIT's audit methodology creates the documentation gap
BAIT is structured around six modules: IT strategy, IT governance, information risk management, information security, IT projects and application development, and IT operations. Each module has documentation requirements — policies, concepts, procedures, registers — that BaFin examiners review during inspections. The audit methodology is document-review heavy. Examiners pull the IT strategy, check it was board-approved within the last twelve months, verify it addresses the required content areas, and move on. They pull the outsourcing register, verify material outsourcing arrangements are classified, check that contracts include the required security clauses. The examination is, structurally, a documentation review with technical spot-checks. That design produces a specific failure mode: institutions that are good at documentation production pass examinations that institutions with stronger actual security posture but weaker documentation fail. The metric being measured is the quality of the paper trail, not the quality of the controls the paper trail describes.
Example
BAIT Section 4 requires a documented information security concept covering security objectives, responsibilities, and specific technical and organizational measures. In examinations, auditors verify the concept exists, is current, and covers the required content areas. They do not independently test whether the technical measures described in the concept are actually implemented. An institution can document network segmentation requirements in a security concept and run a flat network in production. The examination will pass. The network will remain flat.
The distinction matters most in two areas: access management and outsourcing oversight. Both have detailed BAIT documentation requirements. Both have operational realities that diverge from documentation in ways that standard examination methodology does not catch.
What Vulnox found in BAIT-compliant banking environments
Assessment base: Vulnox BAIT gap analyses and digital footprint assessments, 2023 to 2024
Internet-exposed management interfaces belonging to banking IT service providers
In digital footprint assessments of German financial institutions with current BAIT compliance documentation, Vulnox consistently identified external exposure originating from IT service providers rather than the institutions themselves. The pattern: the institution's own perimeter is reasonably well-managed; the IT service provider's infrastructure, which processes and stores the institution's data, has internet-exposed management interfaces, legacy services, or subdomain sprawl that the institution has never assessed. In one case, a management interface for a core banking component was reachable from the public internet on a non-standard port. The institution had no awareness of this. Their outsourcing register documented the service provider. Their contract required the service provider to maintain a defined security standard. Neither the contract nor the register included any mechanism for the institution to verify compliance with that standard.
BAIT Section 25b KWG requires institutions to monitor material outsourcing arrangements. The examination validates that monitoring is documented as a requirement. It does not validate that monitoring is happening. The institution's attack surface includes its service providers' attack surface. An attacker targeting a German savings bank does not need to penetrate the bank's perimeter if the IT service provider running the core banking system has a management interface exposed to the internet.
Privileged access documentation that covers current accounts and misses legacy credentials
BAIT requires documentation of privileged access management as part of the information security module. In assessments of institutions that had produced clean privileged access documentation for recent examinations, Vulnox found a consistent gap between the account inventory used for access reviews and the actual account inventory in production. The gap was most pronounced in three categories: service accounts created during infrastructure migrations that were never registered in the identity governance platform, API credentials issued to third-party integrations that predated the current vendor management process, and administrator accounts on legacy systems outside the standard provisioning workflow. These accounts do not appear in access review records because they are not in the system that generates those records.
The institution can demonstrate to BaFin that their privileged access review process is operating correctly. The process is operating correctly on the accounts it knows about. The accounts it does not know about are the ones that matter to an attacker. This is not a documentation failure — the documentation accurately reflects the governed account set. It is a coverage failure, and it is invisible to examination methodology that validates process quality rather than process completeness.
Annual IT strategy reviews that satisfy BAIT form requirements without strategic substance
BAIT requires the IT strategy to be consistent with the institution's overall business strategy and reviewed annually by senior management. In gap analyses, Vulnox reviewed IT strategy documents from institutions that had passed recent examinations. The documents were formally compliant: current dates, board approval signatures, coverage of required content areas. The strategic substance was in most cases unchanged from the prior year's document, with updated dates and minor edits. The IT strategy described the same IT objectives, the same risk appetite, and the same technology priorities as the year before — in an environment that had undergone significant infrastructure changes, added new IT service provider relationships, and expanded digital channels. The examination validated the document. It did not validate whether the document reflected the institution's actual IT direction.
This is the clearest example of the gap between BAIT compliance and BAIT intent. The IT strategy requirement exists because BaFin wants institutions to have deliberate, senior-management-owned direction for their technology environment. The examination mechanism validates that the document exists and is current. Institutions that understand the mechanism game it — not necessarily cynically, but because annual document review is an achievable compliance task and strategic IT alignment is a harder organizational problem.
What BAIT examinations consistently do not find
The IT service provider's external attack surface
BAIT outsourcing requirements focus on contractual obligations and documentation of the outsourcing relationship. They do not require institutions to independently assess the external attack surface of their material IT service providers. For German savings banks and cooperative banks, where core banking operations frequently run on shared platforms operated by Atruvia or Finanz Informatik, this means the institution's most sensitive operational data is processed on infrastructure the institution has never assessed. The contract says the service provider maintains defined security standards. The examination validates the contract exists. Neither step produces evidence that the service provider's internet-facing infrastructure is actually secure.
Shadow IT accumulated during digital channel expansion
German retail banks expanded digital channels aggressively between 2019 and 2023 — mobile banking applications, digital onboarding workflows, API-based integrations with third-party financial services. Each expansion created new infrastructure: subdomains, cloud environments, API endpoints, development and staging instances. BAIT IT operations requirements cover production infrastructure. Development and staging environments, decommissioned digital products, and API endpoints created for integrations that are no longer active accumulate outside the governance boundary. In digital footprint assessments, these environments consistently appear in external reconnaissance before internal asset inventories identify them.
The gap between BAIT documentation and DORA operational requirements
German financial institutions subject to both BAIT and DORA face a compliance reconciliation problem that most have not yet worked through. DORA's ICT incident reporting requirements have specific timelines — initial notification within four hours of classification, intermediate report within 72 hours — that exceed what most institutions' current incident management processes can support. BAIT requires incident management processes and documentation. It does not specify reporting timelines at the DORA level. Institutions that passed BAIT examinations in 2023 with documented incident management procedures may find those procedures non-compliant with DORA obligations they are now subject to. The documentation that satisfied BaFin last year does not automatically satisfy the DORA technical standards published by EBA.
BAIT, DORA, and MaRisk: how the frameworks interact for German institutions
BAIT versus DORA
BAIT is BaFin-specific national guidance. DORA is EU regulation with direct effect, applying from January 2025. For German financial institutions, both apply simultaneously. The frameworks overlap heavily on ICT risk management and third-party oversight, but DORA introduces requirements BAIT does not have: mandatory ICT incident classification with prescribed reporting timelines, a formal ICT third-party register with specific data fields, and TLPT (Threat-Led Penetration Testing) requirements for significant institutions. BAIT's outsourcing register satisfies some but not all of DORA's third-party register requirements — institutions need to assess the delta and close it, not assume the existing register suffices.
Institutions that structured their BAIT compliance program as their primary IT governance framework now need to run a DORA delta assessment. The question is not whether BAIT compliance transfers to DORA — partial transfer is the honest answer. The question is which DORA obligations are not covered by existing BAIT documentation and processes, and what additional work is required.
BAIT versus MaRisk
MaRisk covers operational risk management broadly across the institution. BAIT is the IT-specific implementation of MaRisk's operational risk requirements. The two frameworks are read together — BaFin examiners conducting a BAIT examination are simultaneously assessing IT-related operational risk under MaRisk. A gap identified in BAIT is simultaneously a gap in MaRisk AT 7.2 (technical-organizational resources). Institutions that manage the two frameworks separately, producing distinct documentation for each, frequently produce inconsistencies: the MaRisk risk inventory describes IT risks differently than the BAIT information risk management documentation, and BaFin examiners notice the inconsistency.
BAIT and MaRisk documentation should be developed as a coherent set, not as separate compliance deliverables. The IT risk register in BAIT information risk management should feed directly into the MaRisk operational risk inventory. Institutions that have separate teams producing each create reconciliation work and examination risk.
Why BAIT-compliant institutions are more exposed than they appear
Common belief
Passing a BaFin BAIT examination means the IT governance program is sound. The examination is conducted by BaFin or its appointed auditors. It covers all six modules. Institutions invest significant resources in examination preparation. A clean examination result is reasonable evidence of a functional program.
What we found
In Vulnox digital footprint assessments conducted after clean BAIT examinations, external exposure originating from IT service provider infrastructure was identified in the majority of engagements. The institutions knew their own perimeter. They did not know their service providers' perimeter. Both are attack surface.
The examination validates documentation quality and process existence. It does not validate control effectiveness or coverage completeness. An institution can have a board-approved IT strategy, a current information security concept, a complete outsourcing register, and documented privileged access management — all accurate, all examination-compliant — while running internet-exposed legacy infrastructure the IT service provider deployed three years ago, maintaining privileged accounts that predate the current governance program, and having no operational process for the continuous outsourcing monitoring that BAIT requires and the examination treats as documented intent rather than demonstrated practice. The examination finds what examinations find: documentation. What attackers find is different. They enumerate subdomains, identify exposed services, map the IT service provider relationships from certificate transparency logs and DNS records, and find the gaps between what the institution documented and what the institution actually runs.
Where BAIT compliance is heading
BaFin will introduce mandatory external attack surface validation requirements for material IT service providers into the next BAIT revision, requiring institutions to produce evidence of independent technical assessments rather than contractual assurances
The current examination gap — validating that service provider contracts include security requirements, without validating that service providers meet them — is structurally identical to the gap that produced the major IT service provider incidents that affected German banking infrastructure in 2022 and 2023. BaFin is aware of this. The DORA technical standards for ICT third-party oversight move in this direction at the EU level. National implementation through BAIT revision is the likely path. The signal to watch: BaFin examination reports from 2025 that cite outsourcing monitoring as a finding category — if the finding rate increases, revision is coming.
Confidence: mediumIf BaFin publishes a BAIT revision by end of 2027 that does not include technical validation requirements for material IT service providers, this prediction is wrong.The DORA-BAIT reconciliation gap will produce a wave of findings in BaFin examinations in 2025 and 2026 as institutions discover their BAIT-compliant incident management processes do not satisfy DORA reporting timelines
DORA applied from January 2025. Most German financial institutions built their incident management processes to satisfy BAIT requirements, which do not specify the four-hour initial notification timeline or the 72-hour intermediate report requirement that DORA mandates. The first wave of DORA-era incidents will reveal the gap. Institutions that passed BAIT examinations with documented incident processes in 2023 and 2024 will find those processes non-compliant with obligations they are now subject to. BaFin examination cycles will surface this systematically from 2025 onward.
Confidence: highIf BaFin examination reports from 2025 and 2026 show no increase in incident management findings compared to prior years, this prediction is wrong.
Whether BAIT examinations are fit for purpose
BAIT is a well-designed framework for the problem it was designed to solve in 2017: bringing German banking IT governance up to a documented, board-level standard. It did that. German financial institutions that went through early BAIT examinations built IT governance programs they did not previously have. The documentation requirements forced conversations about IT strategy and risk appetite that many institutions had never had formally. That was worth doing. The 2021 revision added real substance. But the examination methodology has not kept pace with the attack surface reality of 2024. An examination that validates documentation quality while leaving IT service provider technical posture unverified is not fit for purpose as the primary assurance mechanism for German banking IT security. The framework is better than the audit methodology it runs on. That is the honest assessment.
Counterargument
The counterargument — made by people with legitimate expertise — is that BaFin is a prudential regulator, not a penetration testing firm, and that the examination methodology is calibrated to what regulators can actually do at scale across the German banking sector. Requiring technical assessments of every material IT service provider for every regulated institution would either require an enormous expansion of examination capacity or produce a compliance industry that certifies service providers centrally and creates its own false assurance problem. That is a real constraint. It does not make the current gap in outsourcing oversight acceptable; it makes it structurally hard to close.
One step before your next BAIT examination cycle
Pull the list of material IT service providers in your outsourcing register and identify which ones have internet-facing infrastructure you have never independently assessed. Not audited through their own attestation reports — independently assessed, meaning someone ran external reconnaissance against their subdomains and exposed services from outside their network. For most institutions, the answer is none of them. That is the gap BAIT examinations do not find and attackers do find. A framework gap analysis of your outsourcing oversight program is the formal version. A DNS enumeration of your top three service providers is the version you can do this week. Start there.
Further Reading
Gap Analysis
BAIT gap analysis servicesearch frameworks
related compliance frameworksEMEA compliance frameworks: the complete guide to GDPR, NIS2, DORA, and 40+ regional mandates
BAIT gap analysis for German banking IT supervision complianceUnderstanding Compliance Gap Analysis
compliance gap analysis overviewNIST SP 800-30 Risk Assessment Guide
NIST risk assessment guideThird-Party Risk Management
third-party risk management best practices
Frequently Asked Questions
What does a BAIT gap analysis actually cover?
A BAIT gap analysis maps your current IT governance, security controls, and outsourcing arrangements against the six BAIT modules: IT strategy, IT governance, information risk management, information security, IT projects and application development, and IT operations. The analysis identifies where documented controls exist without operational evidence and where BaFin's evidence expectations exceed what your current processes generate.
What is the most common BAIT compliance gap found in German bank assessments?
Outsourcing control gaps are the most consistent finding. BAIT Section 25b KWG requires continuous monitoring of material IT service providers, but most institutions conduct onboarding assessments and then rely on annual questionnaires. When BaFin examiners ask for evidence of continuous monitoring — access log reviews, configuration change notifications, incident escalation records — institutions frequently cannot produce it for the period between assessments.
How does BAIT differ from DORA for German financial institutions?
BAIT is BaFin-specific and applies to German-licensed institutions. DORA applies across the EU financial sector from January 2025. The two frameworks overlap substantially on ICT risk management and third-party oversight, but DORA introduces mandatory ICT incident reporting timelines and third-party register requirements that go beyond current BAIT obligations. German institutions subject to both must reconcile the differences — DORA does not supersede BAIT, it adds to it.
What evidence does BaFin actually request during a BAIT examination?
BaFin examiners request the IT strategy document and evidence of annual board approval, the information security concept with version history, outsourcing registers with risk classifications, and access management documentation for privileged accounts. They also frequently request incident logs and evidence that the institution's IT service provider has actually been monitored, not just contractually obligated to maintain security standards.
Do institutions using Atruvia or Finanz Informatik need their own BAIT compliance program?
Yes. BAIT accountability sits with the regulated institution, not the IT service provider. Using Atruvia or Finanz Informatik as an IT service provider satisfies some BAIT operational requirements, but the institution remains independently responsible for its IT strategy, risk appetite documentation, information security governance, and oversight of the outsourcing arrangement itself. The service provider's BAIT compliance does not substitute for the institution's own.
How often should a BAIT gap analysis be performed?
BAIT requires the IT strategy to be reviewed and approved at least annually. A gap analysis aligned to that review cycle makes sense operationally. Beyond the annual review, gap analyses should be triggered by material changes: new IT service provider relationships, significant infrastructure changes, regulatory updates, or any incident that revealed a control gap not previously identified.
What is the connection between BAIT and MaRisk for German banks?
MaRisk (Mindestanforderungen an das Risikomanagement) is BaFin's minimum requirements for risk management and covers operational risk broadly. BAIT is the IT-specific implementation — it translates MaRisk's operational risk requirements into concrete IT governance and security obligations. Institutions subject to MaRisk are subject to BAIT. The two frameworks are read together; a gap in BAIT IT controls is simultaneously a gap in MaRisk operational risk management.
Related Articles

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard
GovRAMP Moderate is the first tier where you need a government sponsor, annual 3PAO reassessment, and a Significant Change Request process that can pause normal product releases for months. Most providers who stall post-authorization were not prepared for what maintaining Moderate status actually costs operationally.

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong
GovRAMP Low+ is where providers handling limited Controlled Unclassified Information land — or discover they should not be there. The defining failure is not a missing control. It is a CUI boundary that was drawn before anyone asked what data the government actually sends through the system.

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard
GovRAMP High is where cloud providers discover that having strong encryption is not the same as having FIPS 140-2 validated encryption — and that distinction alone has derailed authorizations from vendors who passed every other control family. The architectural constraints at High are qualitatively different from every lower tier.
Ready to Secure Your Digital Assets?
Get a comprehensive vulnerability assessment for your website today.