Banco Alcalá

Spain · owned by Independent (Spain) · bancoalcala.es · 20 vendors

Banco Alcalá appears to be a Spanish financial institution. The company's website currently shows a 'coming soon' status, indicating it may be in development or launch phase.

Resilience scores

Disruption prediction

Banco Alcalá has an estimated 17% probability of disruption in the next 6 months.

14 of Banco Alcalá's 20 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-07-30 · revision 8

20 direct vendors, 223 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 2/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Banco Alcalá's migration readiness is low, primarily due to a complex regulatory environment and strict data residency requirements. The bank faces 'High' risk and 'Assessment Required' status for critical EU banking regulations (GDPR, NIS2, PSD2, CRD V/CRR II). As a pre-launch entity, it must establish full compliance frameworks, which will be a significant undertaking and constraint for any migration strategy. Data residency requirements are particularly stringent for a Spanish bank operating in the EU, demanding that personal and critical banking data remain within EU/EEA jurisdiction, limiting cloud provider choices and architectural flexibility. The bank's financial stability for funding a major migration is questionable, given the 'coming soon' status, lack of historical revenue data, and 100% revenue concentration in Spain, which could be impacted by the recent service disruptions and potential regulatory fines. While the 'Total Vendors: 0' data is inconsistent with the PayCore Solutions outage, the impact of that outage suggests a degree of vendor lock-in for critical services, which would complicate migration efforts. The absence of specific tech stack details makes it difficult to assess its modernity (cloud-native vs. legacy), but the 'botched software update' incident suggests potential challenges with existing systems that might not be easily migratable. The opportunity to build a modern architecture from scratch exists due to its pre-launch status, but this is overshadowed by the immediate and significant regulatory and data residency hurdles, as well as potential financial constraints.

Compliance

7 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 is primarily relevant for assurance service providers or when banks need to provide assurance reports to stakeholders.

ISAE 3000 is primarily relevant for assurance service providers or when banks need to provide assurance reports to stakeholders. Low risk as it's typically voluntary and situation-specific. May become relevant if the bank offers trust services or needs to provide assurance reports to regulators or large corporate clients.

GDPR (source) — Assessment Required

GDPR applies to all EU-based entities processing personal data. As a Spanish bank, Banco Alcalá will inevitably process customer personal data, employee data, and other personal information.

GDPR applies to all EU-based entities processing personal data. As a Spanish bank, Banco Alcalá will inevitably process customer personal data, employee data, and other personal information. Non-compliance can result in fines up to 4% of annual global turnover or €20 million. Given the bank is in 'coming soon' phase, GDPR compliance framework needs immediate establishment before operations begin.

SOC 2 (source) — Assessment Required

While not mandatory, SOC 2 compliance is increasingly expected by business customers and partners, especially for cloud-based banking services. It demonstrates security controls and operational effectiveness.

While not mandatory, SOC 2 compliance is increasingly expected by business customers and partners, especially for cloud-based banking services. It demonstrates security controls and operational effectiveness. Medium risk as it's voluntary but important for competitive positioning and customer trust in digital banking services.

Financials

Three-year financials

Financial Resilience Score: 8/10

As part of the Creand Group, Banco Alcalá benefits from the financial strength and capital support of a much larger, international entity. The group's solvency is high, with a CET1 (Common Equity Tier 1) ratio of 16.52% as of year-end 2022, well above the regulatory requirements set by the European Central Bank (ECB). This provides a substantial cushion against financial shocks. The bank focuses on private banking and wealth management. This business model is inherently more resilient than commercial or investment banking because its revenues are largely fee-based (from Assets Under Management - AUM) rather than being dependent on credit cycles and trading volatility. The Creand Group maintains a strong liquidity position, with a Liquidity Coverage Ratio (LCR) of 202.85% at the end of 2022. This is significantly above the 100% regulatory minimum, indicating it has more than sufficient high-quality liquid assets to cover its short-term obligations. Operating in Spain, the bank is regulated by the Bank of Spain and the ECB. This ensures a rigorous framework for risk management, compliance, and corporate governance, further enhancing its resilience. The score is not a perfect 10 because, like any wealth manager, its revenues and AUM are susceptible to significant downturns in global financial markets, which can impact client confidence and fee income.

Key strengths: Strong Parentage and Capitalization, Stable Business Model, Liquidity, Regulatory Oversight

Risk factors: Susceptible to significant downturns in global financial markets

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report