Industries & Sectors – IT outsourcing in the financial sector · ISO 27001 & BSI C5

IT outsourcing under BAIT and MaRisk

Banks and financial services providers outsource IT but keep the responsibility. The supervisory authority expects evidence, not promises. centron provides the documents for classification, the information register and provider oversight.

centron Console · Outsourcing file
eu-de · Hallstadt Data Centre
Evidence
C5 / ISO
Location
Germany
DPA
Art. 28
DOC Service description · register
● Ready
ISO ISO 27001 (IT-Grundschutz) · BSI-IGZ-0773
● Valid
C5 BSI C5:2020 Type 1 · unqualified
● Attested
EXIT OpenStack & Kubernetes · portable
● Open
Documents providedTrust Center · outsourcing file
  • Evidence for the review – certificates with scope, C5 attestation, TOMs and DPA in the Trust Center.
  • Register entries – company data, locations and service description ready to record.
  • Certified by the BSI – ISO 27001 based on IT-Grundschutz, issued by the federal office.
  • German contracting partner – centron GmbH, Hallstadt near Bamberg, no foreign parent company.
Why centron

What centron provides for your outsourcing file

With IT outsourcing, the institution remains accountable to the supervisory authority. centron supplies the documents the review demands.

Evidence for the outsourcing review

Certificates with their stated scope, the unqualified BSI C5:2020 Type 1 attestation, TOM documentation under Article 32 GDPR and the data processing agreement under Article 28 GDPR – bundled in the Trust Center.

Entries for your information register

Company data, locations, service description and subcontractor details – in the form in which you record them.

Certified to the BSI standard

ISO 27001 based on IT-Grundschutz, issued by the German Federal Office for Information Security (BSI certificate BSI-IGZ-0773).

German contracting partner

centron GmbH, headquartered in Hallstadt near Bamberg, with no foreign parent company. Customer data is processed exclusively in German data centres.

Outsourcing review

Four questions every outsourcing review asks

Every outsourcing review asks the same questions – here is what centron contributes to the answers.

Is it a material outsourcing?

Whether an outsourcing is material is decided by your risk analysis. centron provides the service description and availability commitments under the service specification for it.

What goes into the information register?

Since DORA, financial companies register all ICT services. centron supplies provider identification, locations and subcontractor details in the required form.

What does the exit strategy look like?

The exit plan describes how operations continue when the arrangement ends. The centron platform builds on open standards such as OpenStack, Kubernetes and S3-compatible interfaces – data and configurations remain portable.

How does provider oversight work?

Ongoing review, risk assessment and documentation remain with the institution. centron supplies up-to-date evidence and dedicated contacts for it.

Responsibility stays in-house

Outsourcing delegates tasks, not responsibility

With IT outsourcing, the institution remains accountable to the supervisory authority. It must demonstrate which provider it has engaged, which services are delivered and how oversight works. centron supplies the service description, certificates with their scope and the register entries. Operational continuity – separate backups, recovery and outage scenarios under DORA – is covered by business continuity management for financial companies.

Outsourcing fileevidence · register entries · DPA
View the evidence in the Trust Center
  • MaRisk – framework for risk management incl. outsourcing
  • BAIT – makes the framework concrete for IT
  • DORA – information register and exit strategy
  • Exit-ready – OpenStack, Kubernetes, S3-compatible
Regulatory landscape

BAIT, MaRisk and DORA at a glance

MaRisk sets the general framework for risk management including outsourcing. BAIT makes it concrete for IT. The DORA regulation has applied directly since January 2025 and brings its own requirements for contracts with ICT third-party providers – what that means for recovery and operational continuity is covered in depth by business continuity management for financial companies.

Regulations and their role
RegulationWhat it governs
MaRiskThe minimum requirements for risk management are a BaFin circular and set the framework for institutions’ risk management, including outsourcing.
BAITThe supervisory requirements for IT in financial institutions make this framework concrete for information technology.
DORADirectly applicable since January 2025, it adds its own requirements for contracts with ICT third-party providers, the information register and the exit strategy.
VAIT · MaGo · KAIT · ZAITParallel versions for insurers, asset management companies and payment service providers – the outsourcing requirements are largely parallel in structure.
Who is responsible for what
TaskWith youWith centron
Risk analysis & classificationin fullsupply of service details
Information register & notificationsin fullsupply of register entries
Provider oversightin fullprovision of up-to-date evidence
Applications & operating systemsconfiguration, patching, operationmanaged service on request
Platform & data centresvirtualisation, network, storage
Datacontrollerprocessor under the GDPR
Recommended building blocks

The right centron products

These are the building blocks institutions typically use to implement IT outsourcing – combinable and expandable at any time.

ccloud³ Virtual Machines
From
3,12 € / month
Applications & databases
  • Certified platform
  • Billed by the hour
  • Root access included
Managed Server
From
53,12 € / month
Operations included
  • Operation, patching, monitoring
  • Dedicated contacts
  • Backups included
Kubernetes
From
29,99 € / month
Open foundation
  • Containerised applications
  • Portable rather than proprietary
  • AutoScaler included
cBacks Backup
Price
on request
Defined retention
  • Separate backup environment
  • Retention to your deadlines
  • Recovery testable
In brief

What does IT outsourcing under BAIT and MaRisk require?

IT outsourcing under BAIT and MaRisk requires a risk analysis with classification, entry in the information register since DORA, an exit strategy and ongoing provider oversight. centron supplies the service description, register entries and evidence: ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773), the unqualified BSI C5:2020 Type 1 attestation, TOM documentation and the DPA. Workloads run on ccloud³ VMs from 3,12 € per month or Managed Servers from 53,12 € per month, portable thanks to OpenStack, Kubernetes and S3-compatible interfaces – exclusively in German data centres. New accounts receive a €200 starting credit.

Building blocks and prices
Building blockPrice
ccloud³ Virtual Machinesfrom 3,12 € / month
Managed Serverfrom 53,12 € / month
Kubernetesfrom 29,99 € / month
cBacks Backupon request
IT outsourcing FAQ

Frequently Asked Questions

What are BAIT and MaRisk?

The minimum requirements for risk management, MaRisk for short, are a BaFin circular and set the framework for institutions’ risk management, including outsourcing. The supervisory requirements for IT in financial institutions, BAIT for short, make this framework concrete for information technology.

Does this also apply to insurers, asset management companies and payment service providers?

Yes. VAIT and MaGo apply to insurers, KAIT to asset management companies and ZAIT to payment service providers. The outsourcing requirements are largely parallel in structure across these versions.

What is a material outsourcing?

An outsourcing is considered material if the outsourced activity is significant for conducting the banking business or financial services. You make the classification yourself based on your risk analysis – centron provides the service description and availability commitments under the service specification for it.

What goes into the information register under DORA?

The information register records all contractual arrangements on the use of ICT services – including the provider with its identification data, the function it supports, the locations of service delivery and its subcontractors. centron supplies these entries in the form in which you record them.

Is centron an ICT third-party provider within the meaning of DORA?

Yes. If you run infrastructure with centron, centron is an ICT third-party provider. This entails requirements for you regarding the contractual arrangements, the entry in your information register and an exit strategy. centron provides the entries and evidence needed for this.

Why does an outsourcing need an exit strategy?

Because business activity must continue even when the outsourcing ends – whether through termination, the provider’s insolvency or a supervisory order. The exit plan describes how operations are brought back into your own systems or transferred to another provider.

How do we avoid dependence on the cloud provider?

The centron platform builds on OpenStack, Kubernetes and S3-compatible interfaces, so data and configurations remain portable. That makes repatriation and provider changes easier – and with them the exit strategy your review requires.

What evidence do we receive for the outsourcing file?

The certificates with their stated scope, the unqualified BSI C5:2020 Type 1 attestation, the documentation of technical and organisational measures under Article 32 GDPR and the data processing agreement under Article 28 GDPR – plus the entries for your information register. Everything is available in the Trust Center.

Where is our data located?

By default in the centron data centre in Hallstadt near Bamberg. The scope of the ISO 27001 certification based on IT-Grundschutz covers Hallstadt, Nuremberg and Frankfurt am Main. No processing takes place in third countries – centron is a German company with no foreign parent company.

Get started for free

Sign up and receive €200 credit at centron within your first 60 days.

This promotional offer applies to new accounts only. Available exclusively to businesses.

What does IT outsourcing under BAIT and MaRisk require?

Outsourcing IT to a cloud provider delegates tasks, not responsibility: the institution remains accountable to the supervisory authority. MaRisk sets the framework for risk management including outsourcing, BAIT makes it concrete for IT, and DORA has added the information register and exit strategy since January 2025. centron provides the documents for the outsourcing file: certificates with their scope (ISO 27001 based on IT-Grundschutz, BSI certificate BSI-IGZ-0773), the unqualified BSI C5:2020 Type 1 attestation, TOM documentation, the data processing agreement and the entries for the information register – operated exclusively in German data centres.