Back to Industries
INDUSTRIES · FINANCIAL SERVICES & INSURANCE

The service was outsourced. The responsibility stayed.

The supervisor has counted: more than two thirds of companies that answered could not transfer an outsourced IT service, or only with difficulty, and more than half could not bring it back in house. We make outsourcing provable — who has access, under which right, evidenced monthly rather than reconstructed before the audit.
DORA since 17.01.2025 Outsourcing · exit · concentration Evidence during operations

The supervisor has counted

In "Risiken im Fokus 2025" BaFin analyses some 24,000 reported outsourcing arrangements from around 2,200 companies. The finding: more than two thirds of the companies that answered say they could not transfer an outsourced IT service to another provider, or only with difficulty. More than half of the companies subject to the reporting duty say they could not perform it themselves again.

That is not a warning about an attacker. It is the observation that the ability to act has left the building while the responsibility stayed behind. Which regime governs it changed in 2026. MaRisk as amended on 30 June 2026 expressly takes outsourced ICT services that fall under ICT third-party risk management per articles 28 to 30 DORA out of the scope of AT 9. ICT outsourcing is therefore governed by articles 28 to 30 DORA. For every other outsourcing arrangement AT 9 still applies, and it holds that outsourcing does not delegate the management body's responsibility to the service provider. Either way the consequence is the same: whoever outsources to their own sector's data centre has not outsourced the duty, only the ability to discharge it themselves.

The same source carries the second finding, which pleases nobody: most IT incidents are not the work of attackers. They arise in the institution's own operations, predominantly through faulty changes, or they arise at the service provider — in around two thirds of payment incidents. An organisation that aims its security spending solely at attackers is addressing the minority of its outages.

What the supervisor finds in inspections

In 2024 ECB banking supervision published what it encounters repeatedly: deficiencies in vulnerability scanning, in the configuration of monitoring systems, in network segmentation and in identity management. 21 percent of institutions reported weaknesses in the design and implementation of their contingency and exit plans. And only 28 percent say all data used by their critical functions comes from an authoritative source.

That last point matters most, even though it sounds the most harmless. Without a source of truth, rights cannot be reviewed, changes cannot be evidenced and an exit cannot be planned. In nearly three quarters, the authoritative source does not cover all critical data — and everything else depends on it.

What we find

Mainframes and older core banking systems whose batch windows set the rhythm for everything else. Identities from decades of mergers that were never consolidated. Privileged access held by the outsourcing provider and standing there permanently. Test environments filled with production data because anything else would be too much effort. And an outsourcing chain whose fourth tier nobody can name any more.

The opposite extreme sits alongside it, in the same institution: home-grown processes in databases, grown over years, doing business-critical work in production — with a static administrator account that has not been changed since it was set up. Both together are typical. One is too big to touch, the other too small to notice.

How to spot a text about DORA that was never checked

DORA has applied since 17 January 2025. What has frequently been written wrongly since then concerns BaFin's circulars.

VAIT, KAIT and ZAIT are withdrawn, and completely so: "Diese Rundschreiben hebt die BaFin mit Ablauf des 16. Januar 2025 auf." — BaFin withdraws these circulars with effect from the end of 16 January 2025. The BAIT, by contrast, remain in force for the institutions that the German financial market digitalisation act only brings under DORA on 1 January 2027. BaFin names them specifically: guarantee banks, financial services institutions such as leasing and factoring firms, housing companies with savings facilities, and third-country branches under § 53 KWG. For that residual group BaFin has set an end date: "Mit Ablauf des 31. Dezember 2026 werden die BAIT daher vollständig aufgehoben." — the BAIT are therefore withdrawn in full with effect from the end of 31 December 2026. From 01.01.2027 the simplified ICT risk management framework of article 16 DORA applies to them. Anyone already within the scope of article 2 DORA applies the regular framework of articles 5 to 15; article 16 is the exception for an exhaustively listed group, not the default.

So anyone writing that DORA has replaced the supervisory IT requirements is wrong for part of the market — and precisely for the part now facing a migration with a deadline.

One more clarification, because it is regularly asserted wrongly: the German critical infrastructure regulation has no insurance sector. § 7 covers cash supply, card-based and conventional payments, and the trading, clearing and settlement of securities and derivatives. § 8 concerns statutory social insurance. KRITIS duties do not reach insurers in this structure; their duties come from DORA.

When one provider fails, many fail

Concentration risk is not theoretical in this market. In 2021 a distributed denial-of-service attack on a cooperative sector service provider took the availability of more than 820 banks down at the same time. In 2026 a data leak at a Munich bank via its IT service provider became public.

Internationally the same pattern appears with more leverage. In the attack on a trading software vendor in early 2023 at least 42 customers had to fall back on manual processing for a time. In the attack on a large bank's US subsidiary in November 2023, unsettled repo transactions rose to 62.2 billion US dollars, against 25.5 billion the day before. In both cases the affected institution was not the market's target but its shared bottleneck.

How to get out of it

Outsourcing becomes provable, not merely contractual. Who exactly accesses which system, under which right, and can that be evidenced monthly. A contract does not answer the question an inspection asks.

The provider's privileged access gets an end. Approval per assignment, a fixed time window, session recording, no permanently stored credentials — including, and especially, at your own sector service provider.

An authoritative data source. Identities, rights and states live in one place and under version control. Without it the exit plan stays a chapter.

Changes as a rehearsed process. They are the most common cause of outages. Automating, reviewing and being able to roll them back reduces incidents more than any additional detection tool.

The exit gets rehearsed once. Not completely and not for everything — but for the one service whose loss stops operations. After that you know whether the plan holds.

Where it pays to start

A survey along the outsourcing arrangements, before anything is procured. In this order: which provider holds privileged access today and since when; which service could you neither move nor bring back in an emergency; where the authoritative source for identities and rights sits; and which home-grown procedures do productive work without appearing on any inventory.

Sources: BaFin, Risiken im Fokus 2025; BaFin notice of 09.01.2025 on the withdrawal of VAIT, KAIT and ZAIT and on the withdrawal of the BAIT by 31.12.2026; BaFin FAQ on the continued application of the BAIT; ECB banking supervision publication on IT and outsourcing findings, 2024; MaRisk, Rundschreiben 06/2026 (BA), as at 30.06.2026, AT 9; BSI-KritisV §§ 7 and 8. Incidents per contemporaneous reporting.

Concrete offerings

What you can hand off

  • Provable outsourcing

    Who accesses which system, under which right — evidenced monthly instead of reconstructed before the audit.

  • Controlled provider access

    Approval per assignment, a fixed time window, session recording, no permanently stored credentials.

  • An authoritative data source

    Identities, rights and states in one place and under version control — the precondition for review and exit.

  • Changes as a rehearsed process

    Automated, reviewed, reversible. The most common cause of outages becomes a planned routine.

  • An exit rehearsal for one service

    Not the whole arrangement, but the one whose loss stops operations — actually played through once.

  • Survey of home-grown procedures

    Find database processes of production significance, assess them, and give them accounts that can be rotated.

Regulatory framework

The four that actually bite

Four bodies of rules decide what actually has to be done inside an institution. Also relevant, depending on the business: PSD2 and strong customer authentication, ISO 27001, and cyber insurers' requirements.

  • DORA
    Digital Operational Resilience Act · applicable since 17.01.2025

    Requires ICT risk management that detects and reports incidents and keeps operations running, plus a register of outsourcing arrangements and testing of resilience. The most expensive part operationally is rarely the technology but the evidence. We build the evidence trail into operations instead of reconstructing it before the review.

  • BAIT · residual group
    BaFin · withdrawal of VAIT, KAIT and ZAIT, BAIT in force until 31.12.2026

    VAIT, KAIT and ZAIT were withdrawn with effect from the end of 16.01.2025. The BAIT remain in force for the institutions that the financial market digitalisation act only brings under DORA on 01.01.2027, and are withdrawn entirely at the end of 31.12.2026; from 01.01.2027 the simplified framework of article 16 DORA applies to them. Generalising this leads to planning your own migration wrongly.

  • DORA art. 28–30
    DORA · ICT third-party risk

    Since the MaRisk version of 30.06.2026, outsourced ICT services no longer fall under AT 9 but under articles 28 to 30 DORA. AT 9 still governs every other outsourcing arrangement. In practice, either way: you have to be able to evidence what happens there in your name — and you need a way back.

  • BSI-KritisV § 7
    BSI-KritisV · finance sector

    The critical services are cash supply, card-based and conventional payments, and the trading, clearing and settlement of securities and derivatives. The regulation has no insurance sector; § 8 concerns statutory social insurance. For insurers the duties come from DORA, not from KRITIS.

Sector facts

As of 2026-09 · Source: dynexo Operations
Typical engagementsMid-tier banks and insurers · institutions with a sector or group service provider behind them
Most common triggersDORA migration, an inspection finding, an incident at the provider, an outsourcing project
Core regulationDORA art. 28–30 for ICT outsourcing · MaRisk AT 9 for the rest · BAIT for the residual group until 31.12.2026 · KRITIS only in payments and securities
What we touch firstThe provider's privileged access, the authoritative data source, the change process
Most common cause of outagesYour own change and the service provider — not the attacker
ExitRehearsed once for the service whose loss stops operations
Operating modelEU, Germany or on-premise · data and logs stay inside the perimeter
Operating levelsManual, automated or by playbook — selectable per area
Asked often

Asked before the briefing

  • We have outsourced everything to our sector service provider. Does this concern us at all?
    Yes, particularly so. Since 30.06.2026 ICT outsourcing is governed by articles 28 to 30 DORA rather than by AT 9, and under both regimes the responsibility stays with the institution regardless of who performs the service. The question in an inspection is not whether your provider works well, but whether you can evidence what happens there in your name.
  • Do the BAIT still apply?
    For some institutions, yes. VAIT, KAIT and ZAIT were withdrawn with effect from the end of 16.01.2025. The BAIT remain in force for the institutions that the financial market digitalisation act only brings under DORA on 01.01.2027 — guarantee banks, financial services institutions, housing companies with savings facilities and third-country branches under § 53 KWG — until they are withdrawn entirely at the end of 31.12.2026.
  • Are we, as an insurer, a KRITIS operator?
    Not under the German critical infrastructure regulation. It has no insurance sector; § 8 concerns statutory social insurance. Your duties come from DORA — which does not make the scope smaller, but the addressees and the evidence are different.
  • Do we have to build everything twice for the exit plan?
    No. The sensible approach is to pick one service — the one whose loss stops operations — and actually walk the way back once. After that you know whether the plan holds, and the review sees a rehearsal rather than a chapter.
Next step

Which service could you neither move nor bring back?

The industry briefing surveys your outsourcing arrangements and privileged access, checks where the authoritative data source sits, and shows which home-grown procedures do productive work without appearing on any inventory.