AI Regulation Tracker · BaFin · Guidance

What does BaFin BDAI principles paper say about AI in banking?

Published Jun 15, 2021 · Last reviewed Oct 5, 2026

BaFin's paper 'Big data and artificial intelligence: Principles for the use of algorithms in decision-making processes', published on 15 June 2021, sets out BaFin's supervisory principles for algorithmic decision-making at financial entities. It describes itself as 'preliminary ideas for minimum supervisory requirements' that form the basis for discussion and can already serve as guidance, and it states that stricter rules for regulated activities take precedence. It has four key principles (management responsibility, risk and outsourcing management, preventing bias, and ruling out legally prohibited differentiation) plus specific principles for the development phase and the application phase. BaFin does not generally approve algorithms; it examines the whole decision-making process, from data source to business process, in a risk-oriented way.

OFFICIAL TEXT: bafin.de ↗ · FINAL · BAFIN

DocumentBaFin BDAI principles paper — Big data and artificial intelligence: Principles for the use of algorithms in decision-making processes
Issued byBundesanstalt für Finanzdienstleistungsaufsicht (BaFin), Germany's Federal Financial Supervisory Authority, working with the Deutsche Bundesbank
TypeGuidance
StatusFinal
PublishedJun 15, 2021
Applies toFinancial entities supervised by BaFin — banks, insurers, asset managers and others — that use algorithms, in particular machine-learning algorithms with considerable complexity, short recalibration cycles and a high level of automation, in decision-making processes. Banks are covered: the paper's use cases include ML-supported credit ratings at a credit institution and sanctions screening for money laundering detection. The paper is non-binding.
Official sourcebafin.de ↗
Use casesModel risk management · AI governance (general) · Fair lending & discrimination · Credit scoring & underwriting · AML / KYC · Data & privacy

What are the key points of BaFin BDAI principles paper?

  • Published 15 June 2021; 16 pages in five chapters: conceptual framework; key principles; specific principles for the development phase; specific principles for the application phase; inclusion of the principles in international regulatory projects.
  • Working definition: AI is the combination of big data, computing resources and machine learning. BaFin says no clear line can be drawn between AI and traditional statistical processes, and the principles apply particularly to algorithms with considerable complexity, short recalibration cycles and a high level of automation.
  • Chapter I: BaFin does not grant a general approval for algorithm-based decision-making processes; it examines them in a risk-oriented way, with the exception of internal models used to determine regulatory capital, where methodology, calibration and validation are examined. Supervision follows 'same business, same risk, same rules' — risk-oriented, proportional and technology-neutral.
  • Chapter II key principles: clear management responsibility (senior management must have sufficient technical expertise and responsibility for decisions based on algorithms); appropriate risk and outsourcing management; preventing bias; ruling out types of differentiation prohibited by law, including through proxies.
  • Chapter III development phase: data strategy and data governance; data protection compliance; accurate, robust and reproducible results; documentation of model selection, calibration and training, and validation; appropriate validation processes performed or examined by an independent function; relevant and representative data for calibration and validation.
  • Chapter IV application phase: putting the human in the loop (involvement must bring real benefits, not mere approval of every decision); in-depth approval and feedback processes, for example a threshold-based process with a final 'stopping rule'; contingency measures for mission-critical applications; ongoing validation, overall evaluation and appropriate adjustments.
  • Worked use cases in the paper: telematics-based insurance rates, NLP analysis of annual reports for credit ratings with random-forest models, sanctions screening for money laundering detection, and algorithm-assisted fund management.
  • Chapter V: BaFin positions the principles as input to the European Commission's Digital Finance Strategy, the European Supervisory Authorities and global standard-setters (FSB, BCBS, IAIS, IOSCO).

What did BaFin BDAI principles paper change for banks?

The paper was the first consolidated statement by a German supervisor of what it expects from algorithmic and AI-based decision-making, and it was published before the EU AI Act was adopted. It does not add new legal requirements; it specifies how existing regulation and administrative practice apply to complex, fast-recalibrating algorithms, and it remains the reference text for BaFin's technology-neutral position that is later built on in the 2022 machine-learning results paper and the December 2025 DORA guidance.

What do BaFin's principles for algorithms in decision-making processes require of banks?

BaFin's 15 June 2021 paper expects banks that use algorithms in decision-making to ensure clear management responsibility with sufficient technical expertise at senior management level, to build risk and outsourcing management suited to algorithmic processes, and to prevent bias and legally prohibited differentiation, including through proxies. For the development phase it expects a verifiable data strategy and data governance, data protection compliance, accurate, robust and reproducible results, documentation of model selection, calibration and validation, independent validation before use and relevant, representative calibration data. For the application phase it expects real human involvement, threshold-based in-depth approval and feedback processes, contingency measures for mission-critical applications and ongoing validation with an overall evaluation. The paper is non-binding and describes itself as preliminary ideas for minimum supervisory requirements, but it states that supervised entities can already use it as guidance.

RuleAuthorityWhat it requiresApplies
Chapter II — Clear management responsibilityBaFinSenior management is responsible for strategies, guidelines and rules on algorithm-based decision-making and for decisions based on algorithms, so it must have sufficient technical expertise and risk-appropriate reporting lines.Published 15 June 2021; non-binding
Chapter II — Appropriate risk and outsourcing managementBaFinEstablish a risk management system adapted to algorithmic processes, analyse and document the likelihood and scale of damage from erroneous decisions, adapt cyber measures (such as against poisoning attacks) and set up effective outsourcing management where service providers are used.Published 15 June 2021; non-binding
Chapter II — Preventing bias; ruling out prohibited differentiationBaFinPrevent biased results and establish statistical verification processes to rule out differentiation on characteristics the law prohibits, including through approximations.Published 15 June 2021; non-binding
Chapter III — Data strategy and data governanceBaFinHave a verifiable data strategy that defines data quality and quantity standards, implemented in a data governance system with clear responsibilities.Published 15 June 2021; non-binding
Chapter III — Accurate, robust and reproducible results; documentationBaFinDocument model selection (weighing prediction quality against complexity and interpretability), model calibration and training, and validation so that internal staff, auditors and supervisors can verify the algorithm.Published 15 June 2021; non-binding
Chapter III — Appropriate validation processesBaFinValidate every algorithm before it enters operations through an independent function or person, define re-validation intervals and ad hoc triggers such as systematic input-data changes or macroeconomic shocks.Published 15 June 2021; non-binding
Chapter IV — Putting the human in the loop; in-depth approval and feedback processesBaFinInvolve employees in interpreting algorithmic results in proportion to how mission-critical the process is, and define in advance threshold-based approval stages, including a stopping rule that triggers ad hoc validation.Published 15 June 2021; non-binding
Chapter IV — Contingency measures; ongoing validation and overall evaluationBaFinDefine measures to keep business operations running if problems arise in mission-critical algorithmic processes, validate algorithms on an ongoing basis and regularly examine risk aggregation across algorithms, ideally with internal or external audit.Published 15 June 2021; non-binding

The paper sits between model risk management and data governance. It asks banks to look at the whole algorithm-based decision-making process from data source to business process rather than at the algorithm alone, which is also how BaFin says it supervises: it grants no general approval for algorithms, examines processes in a risk-oriented way, and approves methodology only where it must, such as internal models for regulatory capital.

Its principles recur in later work. The February 2022 results paper on machine learning in risk models, issued by BaFin and the Bundesbank, positions itself alongside the BDAI principles, and the December 2025 guidance on ICT risks in the use of AI adds the DORA operational-resilience layer. Internationally, BaFin offered the paper as input to the European Commission, the ESAs and global standard-setters.

The paper is guidance, not law. It says it does not rule out stricter rules or administrative practices for particular regulated activities, in which case those take precedence, and it is not an exemption from existing legal and supervisory provisions.

WHAT THIS MEANS IN PRACTICE

  • Map algorithm-based decision processes end to end — data source, model, human review, business process — and assign management-level ownership with technical expertise.
  • Document model selection, calibration and validation, including the reasons for choosing a complex model over a simpler one.
  • Have an independent function validate models before use and define both periodic and event-driven re-validation triggers.
  • Design human review that adds real value (threshold-based escalation and stopping rules) rather than rubber-stamping every output.
  • Test for bias and for proxy variables standing in for characteristics that may not be used, and keep contingency procedures for mission-critical algorithmic processes.

Is BaFin's BDAI principles paper binding?

No. BaFin describes the principles as preliminary ideas for minimum supervisory requirements and a basis for discussion with stakeholders, which can already serve as guidance for supervised entities. It also says the principles do not exempt entities from existing legal and supervisory provisions, and that stricter existing rules take precedence.

Does BaFin approve AI algorithms before banks use them?

No general approval exists. BaFin examines algorithm-based decision-making processes in a risk-oriented way as needed, for example in authorisation, ongoing supervision or supervision of violations. The exception it names is internal models used by banks and insurers to determine regulatory capital requirements, where BaFin examines methodology, calibration and validation.

Does the BaFin paper apply to banks?

Yes. It applies to financial entities supervised by BaFin generally, and its use cases include a credit institution using NLP and random-forest models to supplement credit ratings and a sanctions-screening process for money laundering detection.

How does the BaFin paper compare with the EU AI Act?

The paper predates the AI Act and is non-binding, technology-neutral supervisory guidance centred on governance, validation and human involvement; the AI Act is binding law with risk categories and, for creditworthiness assessment of natural persons, high-risk requirements. BaFin's own current page says it monitors AI Act compliance in the financial sector.

DateDocumentStatus
Dec 18, 2025BaFin guidance on ICT risks in the use of AI — Guidance on ICT Risks in the Use of AI at Financial EntitiesFinal
Feb 18, 2022BaFin/Bundesbank ML in risk models results — Machine learning in risk models – Characteristics and supervisory priorities: Responses to the consultation paperFinal
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force
Jun 24, 2026RBI draft Guidance on Regulatory Principles for Model Risk Management — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments)Proposed
Jun 10, 2026FSB AI sound practices consultation (June 2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation reportProposed
Jun 5, 20262026 BoE/FCA AI survey — The Bank of England and FCA's 2026 AI SurveyFinal

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning