IT outsourcing under BAIT and MaRisk
Banks and financial services providers outsource IT but keep the responsibility. The supervisory authority expects evidence, not promises. centron provides the documents for classification, the information register and provider oversight.
- Evidence for the review – certificates with scope, C5 attestation, TOMs and DPA in the Trust Center.
- Register entries – company data, locations and service description ready to record.
- Certified by the BSI – ISO 27001 based on IT-Grundschutz, issued by the federal office.
- German contracting partner – centron GmbH, Hallstadt near Bamberg, no foreign parent company.
What centron provides for your outsourcing file
With IT outsourcing, the institution remains accountable to the supervisory authority. centron supplies the documents the review demands.
Evidence for the outsourcing review
Certificates with their stated scope, the unqualified BSI C5:2020 Type 1 attestation, TOM documentation under Article 32 GDPR and the data processing agreement under Article 28 GDPR – bundled in the Trust Center.
Entries for your information register
Company data, locations, service description and subcontractor details – in the form in which you record them.
Certified to the BSI standard
ISO 27001 based on IT-Grundschutz, issued by the German Federal Office for Information Security (BSI certificate BSI-IGZ-0773).
German contracting partner
centron GmbH, headquartered in Hallstadt near Bamberg, with no foreign parent company. Customer data is processed exclusively in German data centres.
Four questions every outsourcing review asks
Every outsourcing review asks the same questions – here is what centron contributes to the answers.
Is it a material outsourcing?
Whether an outsourcing is material is decided by your risk analysis. centron provides the service description and availability commitments under the service specification for it.
What goes into the information register?
Since DORA, financial companies register all ICT services. centron supplies provider identification, locations and subcontractor details in the required form.
What does the exit strategy look like?
The exit plan describes how operations continue when the arrangement ends. The centron platform builds on open standards such as OpenStack, Kubernetes and S3-compatible interfaces – data and configurations remain portable.
How does provider oversight work?
Ongoing review, risk assessment and documentation remain with the institution. centron supplies up-to-date evidence and dedicated contacts for it.
Outsourcing delegates tasks, not responsibility
With IT outsourcing, the institution remains accountable to the supervisory authority. It must demonstrate which provider it has engaged, which services are delivered and how oversight works. centron supplies the service description, certificates with their scope and the register entries. Operational continuity – separate backups, recovery and outage scenarios under DORA – is covered by business continuity management for financial companies.
- MaRisk – framework for risk management incl. outsourcing
- BAIT – makes the framework concrete for IT
- DORA – information register and exit strategy
- Exit-ready – OpenStack, Kubernetes, S3-compatible
BAIT, MaRisk and DORA at a glance
MaRisk sets the general framework for risk management including outsourcing. BAIT makes it concrete for IT. The DORA regulation has applied directly since January 2025 and brings its own requirements for contracts with ICT third-party providers – what that means for recovery and operational continuity is covered in depth by business continuity management for financial companies.
| Regulation | What it governs |
|---|---|
| MaRisk | The minimum requirements for risk management are a BaFin circular and set the framework for institutions’ risk management, including outsourcing. |
| BAIT | The supervisory requirements for IT in financial institutions make this framework concrete for information technology. |
| DORA | Directly applicable since January 2025, it adds its own requirements for contracts with ICT third-party providers, the information register and the exit strategy. |
| VAIT · MaGo · KAIT · ZAIT | Parallel versions for insurers, asset management companies and payment service providers – the outsourcing requirements are largely parallel in structure. |
| Task | With you | With centron |
|---|---|---|
| Risk analysis & classification | in full | supply of service details |
| Information register & notifications | in full | supply of register entries |
| Provider oversight | in full | provision of up-to-date evidence |
| Applications & operating systems | configuration, patching, operation | managed service on request |
| Platform & data centres | — | virtualisation, network, storage |
| Data | controller | processor under the GDPR |
The right centron products
These are the building blocks institutions typically use to implement IT outsourcing – combinable and expandable at any time.
- Certified platform
- Billed by the hour
- Root access included
- Operation, patching, monitoring
- Dedicated contacts
- Backups included
- Containerised applications
- Portable rather than proprietary
- AutoScaler included
- Separate backup environment
- Retention to your deadlines
- Recovery testable
What does IT outsourcing under BAIT and MaRisk require?
IT outsourcing under BAIT and MaRisk requires a risk analysis with classification, entry in the information register since DORA, an exit strategy and ongoing provider oversight. centron supplies the service description, register entries and evidence: ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773), the unqualified BSI C5:2020 Type 1 attestation, TOM documentation and the DPA. Workloads run on ccloud³ VMs from 3,12 € per month or Managed Servers from 53,12 € per month, portable thanks to OpenStack, Kubernetes and S3-compatible interfaces – exclusively in German data centres. New accounts receive a €200 starting credit.
| Building block | Price |
|---|---|
| ccloud³ Virtual Machines | from 3,12 € / month |
| Managed Server | from 53,12 € / month |
| Kubernetes | from 29,99 € / month |
| cBacks Backup | on request |
Frequently Asked Questions
What are BAIT and MaRisk?
Does this also apply to insurers, asset management companies and payment service providers?
What is a material outsourcing?
What goes into the information register under DORA?
Is centron an ICT third-party provider within the meaning of DORA?
Why does an outsourcing need an exit strategy?
How do we avoid dependence on the cloud provider?
What evidence do we receive for the outsourcing file?
Where is our data located?
More for the financial sector
Get started for free
Sign up and receive €200 credit at centron within your first 60 days.
This promotional offer applies to new accounts only. Available exclusively to businesses.
What does IT outsourcing under BAIT and MaRisk require?
Outsourcing IT to a cloud provider delegates tasks, not responsibility: the institution remains accountable to the supervisory authority. MaRisk sets the framework for risk management including outsourcing, BAIT makes it concrete for IT, and DORA has added the information register and exit strategy since January 2025. centron provides the documents for the outsourcing file: certificates with their scope (ISO 27001 based on IT-Grundschutz, BSI certificate BSI-IGZ-0773), the unqualified BSI C5:2020 Type 1 attestation, TOM documentation, the data processing agreement and the entries for the information register – operated exclusively in German data centres.