Back to Blog Listing

When Your Banking Vendor Gets A New Owner, Your Register Should Know

When Your Banking Vendor Gets A New Owner, Your Register Should Know
Karol Sobieraj Aug 15, 2026 4 min read

Written by: Karol Sobieraj, Founder & CEO, Digital Colliers

On the surface it looked like a routine strategic investment. ServiceNow took roughly a 5% stake in BusinessNext, a banking software specialist, at around a $700M valuation. For most people that's a headline. For a mid-market bank running BusinessNext, or anything adjacent to it, it's a compliance event that should already be moving through your vendor management system.

And if it isn't, that's the story of this piece.

The deal is a signal, not just news

A minority stake at $700M isn't a full acquisition. But it's a change in the ownership and influence structure of a critical third party. That's exactly the kind of event your vendor register is supposed to catch.

A few things shift when a hyperscaler-adjacent platform takes a position in your banking vendor:

  • The product roadmap gets a new gravitational pull.
  • Data flows may get rerouted through the investor's stack over time.
  • Support, pricing, and contract terms tend to drift within 18 to 24 months.
  • The sub-processor list often changes without loud announcements.

None of this is inherently bad. Some of it may be genuinely good for you. The problem is if you don't know it's happening.

DORA already made this your job

DORA has been in force since 17 January 2025, and it isn't subtle about third-party risk. You're expected to maintain a register of information on all ICT third-party arrangements, keep it current, and be able to hand it to your regulator on request. Change-of-control on a material vendor is not a footnote in that register. It's a field.

The uncomfortable question for most mid-market banks isn't whether they have a vendor register. Most do. It's whether the register knows things like:

  • Who currently owns each vendor, and who has taken a material stake in the last 12 months.
  • Which of those vendors are classified as supporting critical or important functions.
  • Whether the sub-processor chain has changed since the last attestation.
  • What the exit plan looks like if the new owner steers the product somewhere you can't follow.

If a human has to go read TechCrunch to answer those questions, the register isn't doing its job.

The change-of-control signal, wired up

The operators handling this well aren't doing anything exotic. They're treating vendor ownership as a monitored data field, not a static contract clause. The pattern looks something like this:

  1. Every vendor in the register has a canonical entity ID, not just a trading name.
  2. That entity ID is watched against public filings, funding announcements, and M&A feeds.
  3. A change-of-control event opens a ticket, not an email thread.
  4. The ticket routes to procurement, legal, security, and the business owner in parallel.
  5. Within a defined window, the vendor is either re-attested, re-scoped, or flagged for exit planning.

None of that requires a giant platform. It requires someone to decide the register is a live system, not a spreadsheet that gets dusted off before an audit.

This matters more when the vendor sits near automated decisions on customers. The SCHUFA ruling at the Court of Justice already showed that automated credit scoring carries real GDPR exposure, and the AI Act's high-risk obligations for financial services use cases land on 2 December 2027. If your vendor is quietly changing what its models do under new ownership, you own the outcome to the regulator, not them.

The exam finding you don't want

Here's the finding no head of operational risk wants to read back to their board:

"The institution was unable to demonstrate awareness of a material change in ownership of a third-party ICT provider supporting a critical function. The vendor register was not updated to reflect the event, and no reassessment was performed."

That's a paragraph any DORA-competent supervisor can write from public news alone. The fine math on top of it isn't friendly either. GDPR alone reaches up to 20M euros or 4% of global turnover, and DORA sanctions stack on their own footing. Meanwhile the AI Act adds up to 15M euros or 3% of turnover for high-risk violations once its obligations phase in.

So the question after this week's ServiceNow-BusinessNext news isn't really about ServiceNow or BusinessNext. It's simpler.

When your vendor changes owners next quarter, and it will, does your register find out from you, or do you find out from your regulator?

Related Posts