Skip to content
All insights AI governance & compliance in finance

BaFin now reads AI as ICT risk: what DORA asks of your models

BaFin's December 2025 guidance files AI inside DORA's ICT risk regime, not a separate ethics box. Here is what that means for registers, incidents and testing.

3 min read #governance#compliance#dora
Financial services professionals working through an AI initiative

For a couple of years, AI governance in German banking sat in an awkward place. Innovation teams ran the proofs of concept, ethics committees wrote principles, and the people who actually run operational resilience watched from a distance. BaFin’s December 2025 guidance (Orientierungshilfe) closes that gap. It places AI squarely inside ICT risk management under DORA, rather than treating it as an innovation showcase or an ethics question.

That single move changes who owns the problem. An AI system stops being a special case and becomes what DORA already knows how to supervise: a combination of ICT assets and infrastructure. BaFin frames it exactly that way, as models, software, data, hardware, networks and interfaces bundled together. If you can describe a model that precisely, you can register it, test it and report when it breaks.

What “AI as ICT risk under DORA” actually requires

The reframing has concrete consequences. The same controls you already apply to a core banking platform or a payments rail now extend to the model serving fraud scores at two in the morning.

  • Register entries. A material AI system, and the third party hosting or supplying it, belongs in your ICT and third-party register. The model API you buy from a vendor is an ICT service like any other, with the same questions about concentration and exit.
  • Incident reporting. A model that drifts, hallucinates a customer answer or silently degrades can become a reportable ICT incident. You need the monitoring to notice and the classification logic to decide whether it crosses the threshold.
  • Resilience testing. DORA’s testing expectations now cover AI components. That means backtests, eval sets that exercise the failure modes, and scenarios where the model or its data pipeline is unavailable.
  • Documentation and lineage. Where does training data come from, who can touch the weights, how is the version in production traced back to the one that was validated. An audit trail that satisfies a model validation review will usually satisfy DORA too.

None of this is exotic. Most of it is work a serious model validation function should be doing anyway. The shift is that BaFin now expects it under a regime with deadlines and reporting obligations attached.

Why the timing matters

BaFin is set to become the market-surveillance authority for certain high-risk AI systems under the EU AI Act, and it is building that supervisory approach across 2026 even as the Act’s own high-risk deadlines are being pushed back. KI Aufsicht in Germany is being assembled in real time. The honest read is that the supervisor is figuring out its expectations roughly in parallel with the firms it supervises, which is unusual and worth using to your advantage. Documentation you produce now is documentation you can point to later.

The exposure is not theoretical. An EBA survey found AI use rising across EU banking, most commonly in customer-service chatbots, transaction monitoring, fraud detection, risk modelling and credit scoring. Several of those are squarely high-risk under the AI Act and operationally critical under DORA at the same time. A credit-scoring model is a conformity-assessment subject and an ICT asset in one object.

One artefact, two regimes

The practical opportunity in AI governance Germany right now is to stop building parallel paper trails. The AI Act wants a conformity assessment, technical documentation and post-market monitoring. DORA wants register entries, incident classification and resilience evidence. These overlap more than they conflict.

A model card that records lineage, validation results, drift monitoring and version history feeds both. The eval set that demonstrates the model still beats the process it replaced is also resilience evidence. The register entry that names your model vendor is also part of your AI Act supply-chain picture. Build the underlying record once, with enough rigour that it answers a model validator, and you can present the same facts to two supervisors.

The firms that struggle here will be the ones still treating AI as a separate governance silo with its own committee and its own vocabulary. BaFin AI supervision has stopped working that way. Map your models onto the ICT framework you already run, find the gaps, and close them before August.

Working on something similar?

Tell us about your data and the workflow around it, and we will give you a straight read.

Book a 30-min intro call