Governance

VAIT (Insurance Supervisory Requirements for IT)

BaFin's IT regulatory framework for insurance companies in Germany. VAIT mirrors BAIT's structure but addresses insurance-specific requirements for IT governance, security, and outsourcing, and has been updated to align with DORA.

VAIT (Versicherungsaufsichtliche Anforderungen an die IT) is BaFin's counterpart to BAIT, specifically designed for the insurance sector. Published in 2018 and updated to reflect evolving cyber threats, VAIT establishes IT requirements for all insurance companies and pension funds supervised by BaFin.

Like BAIT, VAIT covers IT strategy, governance, information security management, user access management, IT projects, IT operations, outsourcing, and business continuity. However, VAIT includes insurance-specific considerations such as actuarial data management, policy administration systems, and claims processing IT requirements.

With DORA now in effect, VAIT is being harmonized with EU-wide digital resilience standards. Insurance companies must ensure their compliance programs address both VAIT's national requirements and DORA's EU-level mandates, particularly around ICT third-party risk management and incident reporting.

Learn More

Discover how Matproof can help you achieve VAIT (Insurance Supervisory Requirements for IT) compliance.

View framework page

Automate compliance with Matproof

DORA, SOC 2, ISO 27001 — get audit-ready in weeks, not months.

Request a demo