Egencia
United States · www.amexglobalbusinesstravel.com/egencia · 30 vendors
Egencia is a global corporate travel management company that provides a digital platform for businesses to book, manage, and track business trips. It offers technology-driven solutions, including online booking tools, expense management systems, and traveler support. Egencia was acquired by American Express Global Business Travel (GBT) in 2021 and operates as a digital travel management platform under the Amex GBT umbrella.
Resilience scores
- Digital Sovereignty: 77
- Digital Resilience: 4
Technology vendors
- Broadcom Inc. — Technology — United States
- Expensify — Financial Services — United States
- TripActions — Technology — United States
- and 27 more
Services catalogue
1 service in catalogue across 1 category; runs on 30 sub-vendors.
- Travel Management Integration
Insights
Last updated 2026-03-13 · revision 1
30 direct vendors, 252 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 1
- United Kingdom: 1
- France: 1
Subvendors by controlling owner country (sample)
- Romania: 1
- Brazil: 1
- Moldova: 1
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Egencia's migration readiness is assessed as low (25/100) due to a substantial lack of information regarding its core technological landscape, regulatory environment, and financial capacity for a migration initiative. The internal tech stack details (e.g., cloud-native adoption, containerization, microservices architecture), which are crucial indicators of migration ease, are not provided. Similarly, specific regulatory compliance requirements and data residency requirements, which can significantly impact migration strategy and complexity, are unknown. The financial stability required to fund a potentially large-scale migration is also unspecified. Concerning vendor relationships, the "Total Vendors: 0" data point, interpreted as the unknown count of distinct vendors, makes it impossible to assess vendor concentration and its associated lock-in risk, which is a critical factor for migration readiness. While there is geographic diversity among vendor HQs (4 unique countries), this could introduce complexity in managing contracts and relationships during a migration if not properly managed. The explicitly stated "Vendor Lock-in Risk: Unknown" further contributes to the low readiness score, as high vendor lock-in can be a major impediment to a smooth and cost-effective migration. Without details on the existing technology, compliance landscape, and financial resources, Egencia's ability to undertake a successful and efficient migration is highly uncertain.
Compliance
5 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
If Egencia provides assurance services or requires third-party assurance reporting for compliance purposes, ISAE 3000 may be relevant. Medium risk as it depends on specific service offerings and client requirements for assurance reporting.
SOC 2 (source) — Assessment Required
As a technology service provider handling customer data, SOC2 compliance is highly relevant for demonstrating security controls. Travel technology companies face high risk if they cannot demonstrate adequate security controls to enterprise clients. SOC2 Type II reports are often required by large corporate customers.
GDPR (source) — Assessment Required
As a travel technology company likely processing personal data of EU/EEA residents (booking information, traveler profiles, payment data), GDPR compliance is critical. Non-compliance can result in fines up to 4% of annual global turnover or €20 million. Travel companies frequently handle extensive personal data across borders, creating high exposure risk.
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.