Vai al contenuto
[ INDUSTRIES ] / [ FINANCE ]

Software for finance. DORA, NIS2, ICT risk management: ready.

Financial institutions, fintech, insurance, fund managers. You face strict regulatory constraints on business continuity, incident handling, third-party risk. We build software that fits into your compliance framework without generating non-conformities.

[ THE PROBLEMS ]

What we keep seeing.

  • DORA in full application since January 17, 2025

    The entire EU financial sector must have an ICT risk management framework, an incident reporting process, a resilience testing program, structured third-party risk management. Software must support these requirements.

  • NIS2 alongside DORA

    DORA prevails where there is overlap, but NIS2 still applies to non-financial ICT suppliers in the sector and to some essential banks. Coordinating the two regimes requires an integrated compliance approach.

  • Peripheral COBOL systems still in production

    Many Italian financial institutions have peripheral COBOL systems around core banking: reporting, nightly batches, legacy branch systems. The programmers are retiring; knowledge risk is at its peak.

  • Strict constraints on business continuity (RTO/RPO)

    The sector doesn't tolerate unplanned downtime. Multi-zone or multi-region architectures, tested DR plan, 24/7 monitoring are baseline requirements. Custom software must be designed consistently with these.

  • Integration with supervisory systems (Bank of Italy, EBA)

    Reporting to the Bank of Italy, EBA, CONSOB with hard deadlines and specific formats. Software must support prudential reporting flows and DORA incident-notification requirements.

[ HOW WE DO IT ]

The three pillars applied to this industry.

  • [ PILLAR 01 ]

    AI agents and LLM integration

    AI for document automation (KYC, tier-one AML checks, contract reading), RAG on internal knowledge base (operating procedures, regulations). Strict AI Act constraints for high-risk applications: credit scoring, automated decisions, biometrics.

    See the pillar
  • [ PILLAR 02 ]

    Legacy system modernization

    Progressive modernization of peripheral systems (COBOL, AS/400, legacy management systems) without touching the regulated core banking. Strangler pattern, knowledge recovery from the senior team, integration with core systems via documented APIs.

    See the pillar
  • [ PILLAR 03 ]

    Custom software for regulated industries

    DORA-compliant software with integrated ICT risk management framework, designed business continuity, structured audit trail for incident reporting, third-party risk management. ISO 27001-compatible for those certified or on the path.

    See the pillar
[ REGULATIONS ]

The specific rules of this industry.

  • DORA (EU Reg. 2022/2554)

    Digital Operational Resilience Act, applied since January 17, 2025 to the entire EU financial sector. ICT risk management, incident reporting, resilience testing, third-party risk.

  • NIS2 (Italian Legislative Decree 138/2024)

    Applicable to essential banks and to non-financial ICT suppliers in the sector. Coordination with DORA for overlap cases.

  • AI Act (EU Reg. 2024/1689)

    High-risk requirements for AI in credit scoring, fraud detection with automated decisions, customer classification. Transparency, explainability, human oversight.

  • GDPR + MiFID II + EBA Guidelines

    Customer financial data, profiling, retention. Regulatory stratification that requires compliance coordination.

[ FREQUENTLY ASKED QUESTIONS ]

The questions we get most often.

Do you work with financial institutions subject to DORA?

Yes, we build DORA-compliant software for fintechs, paytechs, fund managers, small-to-mid insurers. For systemic institutions (central banks, large insurers) we collaborate as technical specialists alongside their internal teams or dedicated system integrators. Organizational DORA compliance always remains with the client.

Do you have experience with core banking systems?

We don't work directly on core banking (systems typically supplied by specialized vendors: Temenos, Murex, Avaloq, custom). We work on peripheral systems: reporting, dashboards, integration, vertical custom software, AI layers on top of the core. The separation is explicit and contractually framed.

How much does it cost to modernize a peripheral COBOL system?

Typical ranges: €60,000-150,000 for audit + knowledge recovery + first migrated module. €200,000-600,000 for full migration of mid-sized systems. The knowledge-recovery phase from the senior team (including post-retirement consultants) is critical for success.

How do you handle DORA third-party risk?

We provide technical evidence on the software we deliver: architectural documentation, threat model, audit logs, security testing evidence, business continuity plan. We support the client's technical due diligence with this evidence. Contract negotiation and management of the third-party ICT supplier register remains with the client's Legal/Compliance.

[ LET'S TALK ]

Working in Finance?

A real conversation with the people who'll build the software. No automated quotes, no sales bots.

Let's talk