Nordea
Finland · www.nordea.dk · 31 vendors
Nordea is a leading Nordic financial services group operating in northern Europe. It offers a wide range of services including personal banking, commercial banking, wholesale banking, and wealth management to millions of private and corporate customers. The company is headquartered in Helsinki, Finland, and has a significant presence across the Nordic countries.
Resilience scores
- Digital Sovereignty: 13
- Digital Resilience: 5
Disruption prediction
Nordea has an estimated 11% probability of disruption in the next 6 months.
15 of Nordea's 31 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Broadcom Inc. — Technology — United States
- Tealium — Technology — United States
- and 28 more
Services catalogue
5 services in catalogue across 3 categories; runs on 31 sub-vendors.
- Bank integration
- Network co-creation
- Network sponsorship
Insights
Last updated 2026-03-18 · revision 12
31 direct vendors, 294 subvendors
Direct vendors by controlling owner country (sample)
- United States: 25
- Denmark: 1
- Sweden: 1
Subvendors by controlling owner country (sample)
- Unknown: 1
- Hong Kong: 1
- Netherlands: 5
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Nordea exhibits a high level of migration readiness, primarily driven by its advanced and cloud-native technical foundation. The internal tech stack includes extensive use of Microsoft Azure, Google Cloud Platform (GCP), Kubernetes, Docker, and Apache Kafka, alongside modern programming languages like Python and Java with Spring Boot. This indicates a strong existing adoption of cloud infrastructure, containerization, and microservices architecture, which are key enablers for efficient migration and modernization efforts. The presence of an 'Open Banking API Market' also suggests an API-first approach, facilitating integration and data portability. However, several factors introduce complexity and potential challenges to migration. The regulatory environment is stringent, with compliance requirements for GDPR, EU Banking Regulations, and AML, and 'Assessment Required' statuses for NIS2, SOC2, and ISO 27001. These regulations, particularly NIS2, necessitate robust security, data protection, and operational continuity measures that must be meticulously planned during any migration. Strict EU data residency and sovereignty requirements under GDPR, along with potential national data localization rules in Nordic countries, impose significant constraints on where data can be stored and processed in cloud environments. The financial stability required to fund large-scale migration initiatives is unknown. The vendor relationship data is ambiguous, stating 'Total Vendors: 0' but also listing 'Total Services: 65' and 'Vendor HQ Countries' across 8 unique nations. If these services are indeed supported by external vendors, the sheer number of services and the 'Unknown' vendor lock-in risk could complicate migration planning, requiring careful contract review and potential re-platforming or re-integration efforts. Despite these complexities, Nordea's strong technical foundation positions it well for continued migration and cloud optimization.
Compliance
7 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
While SOC2 is not mandatory, it is highly relevant for financial institutions providing digital banking services and processing customer data. As a major bank with extensive digital services (mobile banking, online banking, payment services), SOC2 compliance would demonstrate strong internal controls. Medium risk as it's not legally required but important for customer trust and vendor relationships.
Evidence: https://www.nordea.dk/privat/produkter/digitale-services/
ISAE 3000 (source) — Assessment Required
ISAE 3000 may be relevant for Nordea's assurance reporting, particularly for sustainability reporting and other non-financial assurance services. As a major bank with sustainability commitments, they may use ISAE 3000 for assurance on sustainability reports. Medium risk as it's not mandatory but increasingly important for stakeholder confidence.
Evidence: https://www.nordea.com/da/baeredygtighed/baeredygtighed-hos-nordea
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for financial institutions due to extensive information security requirements and customer data protection needs. While not legally mandated, it's considered best practice for banks. Medium risk as it's not required by law but important for operational security and customer confidence.
Evidence: https://www.nordea.com/da/politik-om-databehandling
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.