{
  "$schema": "https://calibrated-authority.chrishuberreitz.com/schema.json",
  "dataset": "The Calibrated Authority Index",
  "version": "2026-09-22",
  "creator": "Chris Huber Reitz",
  "license": "CC-BY-4.0",
  "id": "bafin",
  "name": "BaFin (Federal Financial Supervisory Authority, Germany)",
  "segment": "financial-regulator",
  "url": "https://www.bafin.de/SharedDocs/Downloads/EN/Aufsichtsrecht/dl_Prinzipienpapier_BDAI_en.pdf?__blob=publicationFile&v=2",
  "scores": {
    "D1": 2,
    "D2": 2,
    "D3": 1,
    "D4": 0,
    "D5": 2,
    "D6": 2
  },
  "ca": 9,
  "posture": "Enabling",
  "c2_fit": "partially",
  "c3": "Evidential",
  "twilight": false,
  "coded_date": "2026-09-20",
  "last_changed": null,
  "revision": 0,
  "quote": "Senior management is responsible for all significant business decisions, even if they are based on algorithms. As a result, senior management must have sufficient technical expertise.",
  "quote_label": "Big data and artificial intelligence: Principles for the use of algorithms in decision-making processes, ch. II Key principles, \"Clear management responsibility\" (primary PDF read 2026-09-20)",
  "provenance": {
    "url": "https://www.bafin.de/SharedDocs/Downloads/EN/Aufsichtsrecht/dl_Prinzipienpapier_BDAI_en.pdf?__blob=publicationFile&v=2",
    "verify_status": "primary-live-2026-09-20",
    "note": "D1=2: \"Sufficient documentation is required in order to ensure that algorithms and the underlying models can be verified - by the company itself and by auditors and supervisors\" (three mandatory documentation steps: model selection, calibration/training, validation); \"users should be able to reproduce results in a subsequent test performed by an independent third party\"; in highly risk-sensitive processes the input data \"should be saved and stored\". D2=2: quoted - accountability is institutional (senior management), not individual authorship. D3=1: no labeling duty of its own; only the cross-reference \"In particular, disclosure requirements vis-a-vis data subjects must also be observed\" under the data-protection principle. Nothing requires a customer to be told an algorithm decided. D4=0: pre-generative document - bias prevention and prohibited differentiation characteristics are covered, but there is no fabrication, hallucination or synthetic-identity provision anywhere in the paper. D5=2: an explicit named principle - \"Putting the human in the loop\": \"Employees should be sufficiently involved in the interpretation and use of algorithmic results when reaching decisions\"; involvement \"should bring real benefits and should not be limited to the mere approval of every algorithmic decision\"; plus the three-threshold approval scheme ending in a \"stopping rule\". D6=2: \"Ensuring accurate, robust and reproducible results\"; initial validation \"should always be performed or at least be examined by an independent function or individual that is not involved in the original modelling process\"; ongoing validation with ad hoc triggers. c2_fit=partially: the papers stated axis is risk magnitude, not proof scarcity - human involvement \"should depend on how mission-critical the decision-making process is and the risks this entails\". But the reproducibility principle and the sanction-screening use case (the algorithm replaces one of two independent checkers precisely because a second human cross-check remains cheap, and a third human enters on disagreement) are verification economics stated outright. Verifiability is layered on top of risk, not the organising principle. c3=Evidential: reproducibility, independent validation, documentation, audit - no relational or professional-identity trust claim anywhere. posture=Enabling: \"BaFin does not generally grant approval for algorithm-based decision-making processes per se\"; the approach is \"risk-oriented, proportional and technology-neutral\" under \"same business, same risk, same rules\". twilight=false: it names blurred calibration/validation boundaries and scaling of error, but frames them as known risk categories rather than precedent collapse."
  },
  "jsonld": {
    "@context": "https://schema.org",
    "@type": "Review",
    "@id": "https://calibrated-authority.chrishuberreitz.com/institutions/bafin",
    "url": "https://calibrated-authority.chrishuberreitz.com/institutions/bafin",
    "name": "Calibrated Authority rating — BaFin (Federal Financial Supervisory Authority, Germany)",
    "datePublished": "2026-09-20",
    "itemReviewed": {
      "@type": "CreativeWork",
      "name": "BaFin (Federal Financial Supervisory Authority, Germany) — public generative-AI policy",
      "url": "https://www.bafin.de/SharedDocs/Downloads/EN/Aufsichtsrecht/dl_Prinzipienpapier_BDAI_en.pdf?__blob=publicationFile&v=2",
      "text": "Senior management is responsible for all significant business decisions, even if they are based on algorithms. As a result, senior management must have sufficient technical expertise.",
      "abstract": "Senior management is responsible for all significant business decisions, even if they are based on algorithms. As a result, senior management must have sufficient technical expertise.",
      "alternateName": "Big data and artificial intelligence: Principles for the use of algorithms in decision-making processes, ch. II Key principles, \"Clear management responsibility\" (primary PDF read 2026-09-20)"
    },
    "reviewRating": {
      "@type": "Rating",
      "ratingValue": 9,
      "bestRating": 12,
      "worstRating": 0,
      "ratingExplanation": "Composite Calibrated Authority score (sum of six 0-2 dimensions). Breakdown — D1 Traceability & inspectability: 2; D2 Human authorship & accountability: 2; D3 Disclosure & labeling: 1; D4 Synthetic-identity / fabrication prohibition: 0; D5 Human validation in loop: 2; D6 Evidential-trust emphasis: 2. Posture: Enabling. Verification-boundary fit: partially. Trust-logic: Evidential."
    },
    "author": {
      "@type": "Person",
      "name": "Chris Huber Reitz",
      "url": "https://chrishuberreitz.com",
      "sameAs": [
        "https://chrishuberreitz.com",
        "https://chrishuberreitz.com/frameworks/calibrated-authority",
        "https://www.linkedin.com/in/chrishuberreitz"
      ]
    },
    "publisher": {
      "@type": "Person",
      "name": "Chris Huber Reitz",
      "url": "https://chrishuberreitz.com"
    },
    "isPartOf": {
      "@type": "Dataset",
      "name": "The Calibrated Authority Index",
      "url": "https://calibrated-authority.chrishuberreitz.com",
      "version": "2026-09-22",
      "license": "https://creativecommons.org/licenses/by/4.0/"
    },
    "license": "https://creativecommons.org/licenses/by/4.0/"
  }
}