Aarhus Universitet

Denmark · www.au.dk · 13 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 13 sub-vendors.

Insights

Last updated 2026-08-15 · revision 1

13 direct vendors, 196 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Aarhus Universitet demonstrates medium-low migration readiness. The internal tech stack appears to be a mix of commercial platforms (Brightspace, PURE, WISEflow) and potentially self-hosted or on-premise systems (TYPO3 CMS, "Webmail (au.dk hosted webmail)"). The presence of specialized infrastructure like "High-performance computing (HPC) for scientific research" and "Bioinformatics and genomics research platforms" suggests complex, potentially difficult-to-migrate components that are not typically cloud-native. There is no information indicating the adoption of modern cloud-native architectures such as containerization or microservices. Significant unknowns exist regarding regulatory compliance and data residency requirements, which for a university in Denmark would likely involve strict GDPR and national data protection considerations, adding complexity to any migration effort. Furthermore, the financial stability and ability to fund a large-scale migration are unknown due to a lack of data on revenue concentration and growth history. While the company uses 17 vendor services, the "Vendor Lock-in Risk" is unknown, and managing multiple vendor contracts across 8 different HQ countries could introduce complexity during a migration. These factors collectively indicate a challenging migration path with considerable effort and risk.

Compliance

9 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for information security management systems (ISMS). While not legally mandated for Danish universities, it is strongly recommended by Danish government IT security guidelines and is increasingly expected for institutions handling sensitive research data, health data, and large volumes of personal data. Aarhus Universitet operates extensive IT infrastructure and processes sensitive data. The Danish government's IT security framework (referencing ISO 27001) applies to public institutions. The risk is Medium because without confirmed ISO 27001 certification, AU's information security posture cannot be independently verified, and gaps could expose the institution to data breaches and GDPR violations.

Evidence: https://medarbejdere.au.dk/informationssikkerhed/, https://www.au.dk/om/profil/privatlivspolitik/, https://www.digst.dk/styring/standarder-og-arkitektur/iso-27001/

Danish University Act — Compliant

Aarhus Universitet operates under the Danish University Act (Consolidated Act No. 778 of 7 August 2019), which governs the establishment, governance, and operations of Danish universities. As a state-funded public university with a functioning board, rector, and administrative structure, AU is in compliance with its foundational legal framework. The risk is Low as this is the institution's primary enabling legislation and non-compliance would be immediately apparent.

Evidence: https://www.au.dk/om/organisation/, https://www.au.dk/aarsrapporter, https://www.retsinformation.dk/eli/lta/2019/778, https://www.rigsrevisionen.dk/

Danish Act on Research Ethics — Assessment Required

Aarhus Universitet conducts extensive health science research requiring ethical approval from the Danish National Committee on Health Research Ethics (De Videnskabsetiske Komitéer). Non-compliance with research ethics requirements can result in project suspension, legal liability, and reputational damage. The risk is Medium because AU has established research ethics infrastructure, but the volume and diversity of research projects creates ongoing compliance obligations.

Evidence: https://www.au.dk/om/kontakt/personoplysninger-i-forskning-paa-aarhus-universitet-hvor-vi-er-dataansvarlige, https://medarbejdere.au.dk/index.php?id=431001, https://www.nvk.dk/

Financials

Three-year financials

Financial Resilience Score: 8/10

Aarhus University demonstrates strong financial resilience as a self-governing Danish state institution. Its revenue base is anchored by stable Finance Act government subsidies (~DKK 5.0bn annually, ~55% of revenue) that are politically supported, with the November 2025 Danish Research Agreement adding DKK 93m/year in permanent basic funding. External research funding has grown +50.5% cumulatively over 4 years, reaching DKK 3.38bn in 2025, with DKK 9.2bn of committed but unspent grants providing multi-year visibility. Solvency has improved markedly from 11.1% (2022) to 20.3% (2025), and equity has more than doubled from DKK 631m to DKK 1,384m. Liquidity is strong with DKK 3.39bn in cash and securities and a liquidity ratio of 118%. The 2025 profit of DKK 306m materially beat budget (DKK 103m), and audit opinions from Deloitte and Rigsrevisionen were unqualified. The institution ranks 15th-largest recipient of EU Horizon Europe funding cumulatively. Key risks include concentration on Danish state funding (no geographic diversification), sensitivity to political decisions such as the Master's reform cutting Bachelor intake by 9.5%, planned government administrative cost cuts for 2027–2030, and financial-items volatility (2022 saw a DKK ~250m mark-to-market securities loss). Major Campus 3.0 capex will produce small budgeted deficits in 2028–2029, though these are funded from earmarked equity. Overall, the combination of stable state funding, growing external grants, strong liquidity, and improving solvency supports a high resilience score.

Key strengths: Stable Finance Act government funding of ~DKK 5.0bn/year (55% of revenue), Improving solvency ratio from 11.1% (2022) to 20.3% (2025), Strong liquidity: DKK 3.39bn cash and securities, 118% liquidity ratio, DKK 9.2bn of committed but unspent external grants providing multi-year visibility, External funding grew +50.5% cumulatively over 4 years, Unqualified audit opinions from Deloitte and Rigsrevisionen, New DKK 93m/year permanent funding from Nov-2025 Danish Research Agreement, Equity more than doubled from DKK 631m (2022) to DKK 1,384m (2025)

Risk factors: Concentration on Danish state funding (~74% of revenue from Danish sources), Political sensitivity: Master's reform cutting Bachelor intake by 9.5%, Planned government administrative cost cuts for 2027–2030, Financial-items volatility (DKK ~250m adverse swing in 2022), Non-cancellable rent obligations of DKK 1.19bn through 2034, Campus 3.0 capex driving budgeted deficits in 2028 (-DKK 6m) and 2029 (-DKK 3m), Contingent property-tax dispute with Aarhus municipality (~DKK 24m), Grant clawback risk (3-10 year window on external grants), Declining student FTEs (27,172 in 2021 → 26,636 in 2025)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report