Karsten Wenzlaff, Advisor
August 26th, 2025
Aug 17, 2026

When the first DORA Register of Information submissions arrived in April 2025, European supervisors kept hitting the same wall. Financial entities could not produce an accurate, current list of their own ICT assets. The data sat in spreadsheets, in a departed engineer's notes, and across two or three tools that disagreed with each other. The EBA flagged widespread gaps and sent institutions back to resubmit, in several cases more than once.
None of that was a security failure in the usual sense. The controls were often in place. What was missing sat one level lower: a reliable inventory of what the firm actually runs. For a fintech, that absence is not a documentation nuisance. Operational resilience – keeping payments, ledgers, and customer access working through a disruption – rests on knowing what you run, where it runs, and what stops when a component fails. You cannot map a dependency you never recorded, and you cannot restore a service whose parts you cannot name.
DORA (Regulation (EU) 2022/2554), in force since 17 January 2025, states the requirement plainly. Article 8 obliges financial entities to identify and classify all ICT assets and information assets, document the links and interdependencies between them, and keep those inventories current – refreshed after every major change, with a dedicated risk assessment of legacy systems at least once a year. DORA requires EU member states to lay down effective, proportionate and dissuasive penalties for financial entities. The sanctions that apply depend on national law and on the circumstances of the breach.
The UK sets a parallel bar. Under FCA policy statement PS21/3 and PRA supervisory statement SS1/21, the transitional implementation period ended on 31 March 2025. Firms must identify their important business services, set impact tolerances, and map the resources each service depends on, including technology, data, facilities, and people. That mapping collapses without an accurate asset layer beneath it. In the US, the 2020 interagency paper on operational resilience points the same way, tying resilience to a clear view of critical systems and their dependencies.
Enforcement is tightening rather than loosening. Germany's BaFin declared the DORA “transformation year” over at the end of 2025, a signal that supervisors now expect working inventories, not remediation plans. Three regulators, one shared premise: transparency of IT assets is the precondition for everything built on top of it.

Figure 1
Figure 1. IT asset transparency is the base layer every resilience process depends on.
Transparency is not a spreadsheet exported once a quarter. It is three capabilities working together, and the weakest one sets the ceiling.
Automated hardware and software auditing finds devices, virtual machines, cloud instances, and installed packages without waiting for anyone to complete a form. Fintechs churn infrastructure quickly, so a hand-maintained list is stale within weeks. Agent-based and agent-less scanning each catch what the other misses – agents report from laptops that leave the network, while agent-less scans reach devices where you cannot install software.
A configuration management database (CMDB) records that a specific payment API runs on these servers, reads from that database cluster, and backs a named customer-facing service. During an incident, that relationship graph gives you blast radius in seconds instead of a war-room reconstruction. A flat asset list cannot answer the question that matters: if this fails, what else goes with it?
Every asset needs a criticality rating, a named owner, a lifecycle state, and a link to the business function it supports. That is close to a word-for-word restatement of what DORA Article 8 asks a financial entity to hold, which is why an inventory missing those fields tends to fail at submission time rather than during an outage.
Table 1. What each resilience obligation actually needs from the asset layer.
| Resilience obligation | Asset data it requires | Consequence of a gap |
| DORA Article 8 inventory and classification | Full list of hardware, software, and cloud services with a criticality rating and named owner | Incomplete Register of Information; repeated resubmission cycles |
| Dependency mapping (DORA Art. 8; UK important-business-service mapping) | CMDB relationships tying assets to services, users, and third parties | Cannot scope incident impact or evidence a recovery path |
| Incident response and recovery | Live location, configuration, and ownership for every asset | Longer time-to-restore; recovery steps improvised during the outage |
| Yearly legacy-system risk review | Lifecycle state, end-of-life flags, and patch status | End-of-life systems stay live and unassessed |
| Third-party and concentration risk | Register of vendor-linked assets and their interconnections | Blind to a supplier dependency during a supplier outage |
The failure modes are predictable. Cloud and SaaS growth push assets outside the corporate network, where an on-network scanner never sees them. Shadow IT – a product team standing up a service on a corporate card – never reaches the register at all. Remote and field laptops drop off the VPN and stop reporting, so their patch state quietly goes unknown. And the most common failure is the humblest one: the inventory lives in spreadsheets and email threads that no discovery tool feeds, so it drifts out of date the moment it is saved.
The dataset behind Alloy Software's recent deals shows how entrenched that last pattern is. Across more than 40 closed-won accounts between 2024 and 2026, spreadsheets, email, and homegrown databases were the single most common system teams were replacing – ahead of any named commercial tool.

Figure 2
Figure 2. Prior systems replaced across 40+ Alloy Software closed-won deals (2024–2026).
A workable sequence follows the order of dependency, not the order of visible output:
The order matters. Teams that start with dashboards before discovery end up with attractive reports built on data nobody trusts. Discovery first, relationships second, reporting last.
For a regulated fintech, three questions filter the market quickly. Does discovery reach cloud and off-network devices? Does the CMDB model relationships rather than store a flat list? Can the data stay on-premises where a security policy or air-gapped requirement demands it? Cost matters, but it rarely decides the outcome on its own.
Table 2. Decision view across five ICT asset and service-management platforms.
| Platform | Discovery reach | CMDB and relationships | Hosting | Indicative cost / fit |
| Alloy Navigator | Agent and agent-less network inventory; off-network audit for field laptops | Integrated CMDB; tickets linked to assets, users, and contracts | On-prem or cloud | ~$1k–$25k/yr; 2–35 IT staff |
| ServiceNow | Agent-less discovery via MID server; broad cloud coverage | Deep, highly configurable CMDB | Cloud-first; limited on-prem | Six-figure programmes; 100+ IT staff |
| Lansweeper | Agent and agent-less scanning; strong network coverage | Asset-centric; lighter service relationships | Cloud or on-prem | Per-asset pricing that has risen sharply; small–mid teams |
| ManageEngine ServiceDesk Plus | Agent and agent-less; discovery add-on | CMDB in higher tiers | On-prem or cloud | Low–mid, per-technician/node; small–mid teams |
| Freshservice | Discovery agent plus probe | Cloud-native CMDB | Cloud only | Per-agent SaaS; no on-prem option |
Costs reflect market positioning, not quotes; verify against current vendor pricing before shortlisting.
Where a firm has outgrown spreadsheets but cannot absorb a six-figure ServiceNow programme, mid-market platforms cover the ground. Alloy Navigator sits in that band: agent and agent-less network inventory, an integrated CMDB that links tickets to assets, users, and contracts, and a choice of on-premises or cloud hosting for healthcare, public-sector, and finance environments with strict data-residency rules. Deal data puts its annual cost between roughly $1,000 for small teams and $25,000 for larger estates, which is why it usually appears against Lansweeper and ManageEngine rather than enterprise suites.
An accurate asset register earns its keep only when it feeds the processes around it. Change management is the clearest example: when every change references the assets and services it touches, the CMDB stays current as a by-product of daily work instead of decaying between audits. Incident response reads the same relationship graph to scope impact, and third-party risk mapping – a specific DORA obligation – draws on the register of vendor-linked assets. Teams that want to go deeper on tying assets to change and incident workflows tend to find that the relationship model, not the raw asset count, is where the resilience value sits.
If a fintech can answer three questions on demand – what do we run, what depends on it, and who owns it – most of DORA Article 8 and the UK mapping requirement is already within reach. If it cannot, no volume of policy documentation closes the gap, because the gap is data, not paperwork. Point automated discovery at the whole estate, including cloud and remote endpoints, and measure how far the result differs from the current spreadsheet. That delta is the honest size of the resilience problem.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Leave a Reply