Finanstilsynet
www.finanstilsynet.dk · 7 vendors
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 8
- Financial Resilience: 9
Technology vendors
- Akamai Technologies, Inc. — Technology — United States
- Microsoft Corporation — Technology — United States
- One.com Group AB — Technology — Denmark
- and 6 more
Insights
Last updated 2026-07-28 · revision 2
7 direct vendors, 113 subvendors
Direct vendors by controlling owner country (sample)
- United States: 2
- United Kingdom: 1
- Japan: 1
Subvendors by controlling owner country (sample)
- Australia: 2
- France: 2
- Israel: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Finanstilsynet shows moderate to good migration readiness. The presence of cloud-based components such as Microsoft Azure AD and Azure CDN indicates existing experience and comfort with cloud infrastructure, which is a positive foundation for further cloud migration. The strategic move from 'FIONA Online' to 'e-Reg' for EU supervisory reporting suggests an ongoing modernization effort and a willingness to adopt new platforms and technologies, potentially leveraging more agile or cloud-native architectures, though specific details like containerization or microservices are not provided. The dedicated 'DCIS' unit, with its focus on DORA compliance, implies that Finanstilsynet is actively addressing the regulatory complexities associated with digital operational resilience, which is crucial for managing compliance during a migration. The geographic diversity of their vendor base (HQ in Denmark, US, Australia; owners in Denmark, US, Australia, UK, Japan) suggests a reduced risk of extreme vendor lock-in from a single source, offering more flexibility in choosing migration partners or alternative solutions. However, the highly regulated nature of the financial industry means that any migration would need to meticulously address stringent compliance requirements, data integrity, and security protocols. Key unknowns include specific data residency requirements, which can significantly impact migration strategies, and financial stability data, which would indicate their capacity to fund a large-scale migration. While vendor diversity is present, the exact number of distinct vendors and the complexity of existing contracts (vendor lock-in risk) are not specified, which could pose challenges.
Compliance
11 in-scope frameworks identified; showing 3.
Danish Public Administration Act — Compliant
As a Danish public authority, Finanstilsynet is subject to the Danish Public Administration Act (Forvaltningsloven) governing administrative procedures, and the Danish Access to Public Records Act (Offentlighedsloven) governing transparency and public access to documents. These are foundational legal requirements for all Danish public authorities. Finanstilsynet's supervisory secrecy obligations under §354 of the Financial Business Act create specific carve-outs from general public access rules for supervisory information. Risk is Low as these are core operational requirements for a public authority.
Evidence: https://www.finanstilsynet.dk/vores-organisation/privatlivspolitik, https://www.finanstilsynet.dk/vores-organisation/finanstilsynets-opgaver
NIS2 (source) — Assessment Required
NIS2 targets private-sector Essential and Important Entities in listed sectors (banking, financial market infrastructure, public administration, digital infrastructure, etc.) and applies to medium/large enterprises (50+ employees or €10M+ turnover). Finanstilsynet is a Danish government agency (public administration) under the Ministry of Business. NIS2 does include 'public administration' as an Essential Entity sector (Annex I), but Denmark's NIS2 implementation (Lov om sikkerhed i net- og informationssystemer, in force January 2025) may carve out certain central government bodies or treat them differently under national law. As the financial sector regulator, Finanstilsynet is deeply engaged with NIS2 and DORA compliance for the entities it supervises, and it operates the DCIS (Decentral enhed for cyber- og informationssikkerhed for finanssektoren). Risk is LOW because: (1) even if NIS2 applies to Finanstilsynet as a public administration entity, it already operates robust cybersecurity practices as a financial regulator; (2) it is connected to Center for Cybersikkerhed; (3) it actively supervises NIS2/DORA compliance for others, indicating deep institutional knowledge. Missing information: Denmark's specific NIS2 national implementation scope for central government agencies needs formal legal review.
Evidence: https://www.finanstilsynet.dk/vores-organisation/samarbejdsaftaler-og-raad/dcis, https://www.finanstilsynet.dk/finansielle-temaer/tilsyn-med-ikt-og-datasikkerhed, https://www.finanstilsynet.dk/vores-organisation/finanstilsynets-opgaver
AML — Compliant
Finanstilsynet is the primary AML/CFT supervisory authority for the Danish financial sector. It conducts AML inspections (Hvidvaskinspektion) of regulated entities and administers the Danish AML Act (Hvidvaskloven). As the AML supervisor, Finanstilsynet is inherently compliant with AML regulatory requirements in its supervisory capacity. Risk is Low as Finanstilsynet is the enforcer, not a regulated entity subject to AML obligations in the traditional sense (it does not conduct financial transactions on behalf of customers).
Evidence: https://www.finanstilsynet.dk/finansielle-temaer/hvidvask, https://www.finanstilsynet.dk/lovgivning/dansk-lovsamling/hvidvaskomraadet, https://www.finanstilsynet.dk/ansoeg-og-indberet/indberetninger-til-fiona-online/amlctf
Financials
Three-year financials
- 2024: revenue DKK 507.6M, EBIT DKK 5.9M, equity DKK 24.5M
- 2023: revenue DKK 414.9M, EBIT DKK -21.1M, equity DKK 23.3M
- 2022: revenue DKK 434.9M, EBIT DKK 14.4M, equity DKK 47.2M
Financial Resilience Score: 9/10
Finanstilsynet is a Danish government regulatory agency with an exceptionally strong financial resilience profile due to its status as a state entity backed by the Danish sovereign. It is 100% self-financing via statutory fees levied on all supervised financial entities under Danish law (Lov om finansiel virksomhed §§ 360–370), which allows it to adjust fees annually to match its finance-act appropriation. This creates extremely predictable revenue that is decoupled from market or economic cycles because the fee base (financial sector balance sheets) is broad and mandatory. The agency maintains positive net equity of approximately DKK 24 million (state capital of DKK 8.4 million plus accumulated retained surplus of ~DKK 16 million at end-2024) and has significant unused borrowing capacity, with only 38.3% of its DKK 30 million state loan facility utilized at end-2024, down from 68.1% in 2022. Its growing statutory scope from EU regulations (DORA, NIS2, CSRD, MiCA, IRRD) mechanically raises its budgetary allocation. Key risks include dependency on the Danish Finance Act appropriation, oversight risk from Rigsrevisionen (state audit), cost pressure from rapid headcount growth (14% FTE growth from 2022 to 2024), and talent retention challenges with historically high turnover rates (21% in 2022, declining to 12.6% in 2024). However, as a state entity, it cannot fail in a commercial sense and has effectively AAA-equivalent credit standing.
Key strengths: 100% self-financing via statutory fees on supervised financial sector, Danish sovereign backing (effectively AAA-equivalent), Positive net equity of ~DKK 24M with state capital of DKK 8.4M, Only 38.3% utilization of DKK 30M state loan facility, Predictable revenue decoupled from economic cycles, Growing statutory scope from EU regulations (DORA, NIS2, CSRD, MiCA), Planned break-even for 2025 budget (DKK 540.6M income = expenses)
Risk factors: Full dependency on Danish Finance Act appropriation, Rigsrevisionen (state audit) oversight risk - 2022 surplus was flagged as excessive, Cost pressure from 14% FTE growth (2022-2024) and 22% salary spend growth, Talent retention challenges in specialist IT, cyber, and legal roles, Case-processing pressure - missed 100% on-time legal deadline target in 2024 (98.6%), Personnel costs at 65% of income creates operating leverage risk
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Statutory sector fees (financial supervision): 99%
- Fine income and other: 1%
Workforce by country
- Denmark: 414
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.