Client Success Stories

“DORA: INFORMATION NETWORK”

Creating transparency across critical business processes, IT services, systems and their interdependencies — through holistic mapping of the information network in ServiceNow.

The Customer

Kreis 1

Sector

Financial Services

Kreis 1

Turnover

500 M - 5 BN

Kreis 1

Employees

2.000 – 10.000

Initial Situation

With regulatory requirements such as DORA, BSI Basic Protection and VAIT coming into force, financial institutions are required to create full transparency across their information networks.

For an insurance company, this meant systematically defining and mapping critical business processes, IT services, systems and assets within ServiceNow.

At the same time, efficiency and transparency within IT governance and IT security needed to be increased. This required the introduction of a standardised IT service catalogue and the establishment of Service Asset and Configuration Management (SACM) as the foundation for controlling configuration items and ICT assets.

The information network thus became a central pillar for regulatory compliance, security and service‑oriented IT management.

The information network is a critical foundation for IT security, operational stability and regulatory compliance — especially in highly regulated industries such as insurance and banking.

Objectives

  • Compliant representation of the information network in line with DORA, BSI Basic Protection, VAIT and ISO 27001
     
  • Introduction of a company‑wide, standardised IT service catalogue in ServiceNow
     
  • Establishment of centralised Service Asset and Configuration Management (SACM)
     
  • Introduction of ICT asset management to ensure transparency, control and compliance

Our Assignment

With the mandatory application of DORA from 2025, the organisation initiated preparatory measures to reduce IT security risks and meet upcoming regulatory obligations.

The objective of the engagement was to define the information network in a structured, compliant and transparent way - and to lay the foundation for a service‑oriented operating model across the entire organisation.

Challenges

  • Structuring and mapping IT and business services across the organization
  • Insufficient data quality and completeness within the ServiceNow CMDB
  • Acceptance barriers during the introduction of ServiceNow and new ways of working

Measures

  • Introduction of clear service ownership and identification of service experts
  • Integration of relevant source systems to ensure complete, high‑quality CI data
  • Targeted communication and training to drive adoption and service orientation

KC Process Model

The successful implementation of the project was driven by close collaboration between the client and Karer Consulting across the entire lifecycle — from initial concept and objective setting to implementation, go‑live and hypercare.

End‑to‑end responsibility, combined with proven best practices and regulatory frameworks, ensured sustainable implementation and laid the foundation for future service orientation.

In the IT Service Catalogue workstream, a clear target structure for ServiceNow was designed specifically for the financial industry. This structure served as the basis for populating the service catalogue and integrating individual client requirements through joint workshops.

In Service Asset & Configuration Management (SACM), the focus was on connecting all relevant source systems to ServiceNow to enable consistent CI provisioning. Process design and targeted training ensured organisational adoption.

For ICT Asset Management, dependencies between assets and services were systematically captured and mapped to ensure transparency and compliance.

Comprehensive test management, including interface and authorisation testing, enabled a controlled and smooth transition into production.

 

Kreis 2

“Integrated information networks eliminate silos — and create transparency that benefits every level of the organisation.”

Karolina Teter
Senior Consultant Karer Consulting

Customer Benefits

Transparency

Clear visibility of services, systems, assets and their dependencies.

Security

Improved response capability in the event of disruptions or cyber incidents.

Regulation

Demonstrable compliance with DORA and related regulatory requirements.

A consistent representation of the information network provides the foundation for security, resilience, efficiency – and compliance with legal requirements.