Danske Bank A/S

Denmark · owned by Independent (Denmark) · danskebank.com · 49 vendors

Danske Bank is a Nordic bank with strong local roots and bridges to the rest of the world. The bank operates across Denmark, Finland, Norway, Sweden, and Northern Ireland, providing banking services to personal and business customers.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 49 sub-vendors.

Insights

Last updated 2026-09-13 · revision 6

49 direct vendors, 376 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Danske Bank exhibits a high degree of migration readiness, largely driven by its advanced and cloud-native oriented tech stack. The extensive use of Microsoft Azure, AWS, Kubernetes, Docker, Apache Kafka, Spring Boot, React, and Node.js, coupled with a focus on API-first architecture, DevSecOps, and microservices, provides a highly adaptable and modular foundation for migrating to modern cloud environments. The bank's stable financial position, characterized by consistent revenue and a focus on operational efficiency, suggests it has the necessary resources to fund complex migration initiatives. Despite these strengths, several factors present potential challenges or unknowns for migration. The 'Vendor Lock-in Risk' is unknown, which is a critical concern; significant lock-in across its '145 services' could lead to substantial complexities, costs, and delays in re-platforming or renegotiating contracts during a migration. The sheer number of services (145) implies a broad portfolio of systems and potentially numerous vendor relationships, which can complicate coordination, integration, and data migration efforts. Furthermore, the absence of specific data on regulatory compliance and data residency requirements is a significant gap. For a banking institution, these are often stringent and can impose considerable constraints on migration strategies, particularly concerning cross-border data movement or specific cloud provider certifications. While vendor geographic diversity is beneficial for resilience, managing a large-scale migration involving many geographically dispersed vendors could also introduce coordination complexities.

Compliance

8 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

Danske Bank operates in the banking sector, which is explicitly listed as an Essential Entity under NIS2. As a large Danish bank with significant operations across the Nordic region, it clearly exceeds the size thresholds (50+ employees, €10M+ turnover). Non-compliance with NIS2 can result in substantial fines and operational restrictions. The banking sector faces heightened cybersecurity risks, making compliance critical.

Evidence: https://danskebank.com

Basel III — Assessment Required

As a significant Danish bank, Danske Bank is subject to EU banking regulations implementing Basel III through CRD IV. These regulations are mandatory for banks and include capital adequacy, liquidity, and risk management requirements. Non-compliance can result in severe penalties, operational restrictions, and potential loss of banking license.

Evidence: https://danskebank.com

AML — Assessment Required

Anti-Money Laundering and Counter-Terrorism Financing regulations are critical for banks. Danske Bank has faced significant AML challenges in the past, making ongoing compliance essential. Non-compliance can result in massive fines, criminal liability, and loss of banking licenses. The bank's previous AML issues increase the risk profile significantly.

Evidence: https://danskebank.com

Financials

Three-year financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report