Initial Situation
With regulatory requirements such as DORA, BSI Basic Protection and VAIT coming into force, financial institutions are required to create full transparency across their information networks.
For an insurance company, this meant systematically defining and mapping critical business processes, IT services, systems and assets within ServiceNow.
At the same time, efficiency and transparency within IT governance and IT security needed to be increased. This required the introduction of a standardised IT service catalogue and the establishment of Service Asset and Configuration Management (SACM) as the foundation for controlling configuration items and ICT assets.
The information network thus became a central pillar for regulatory compliance, security and service‑oriented IT management.
Objectives
- Compliant representation of the information network in line with DORA, BSI Basic Protection, VAIT and ISO 27001
- Introduction of a company‑wide, standardised IT service catalogue in ServiceNow
- Establishment of centralised Service Asset and Configuration Management (SACM)
- Introduction of ICT asset management to ensure transparency, control and compliance
With the mandatory application of DORA from 2025, the organisation initiated preparatory measures to reduce IT security risks and meet upcoming regulatory obligations.
The objective of the engagement was to define the information network in a structured, compliant and transparent way - and to lay the foundation for a service‑oriented operating model across the entire organisation.
KC Process Model
The successful implementation of the project was driven by close collaboration between the client and Karer Consulting across the entire lifecycle — from initial concept and objective setting to implementation, go‑live and hypercare.
End‑to‑end responsibility, combined with proven best practices and regulatory frameworks, ensured sustainable implementation and laid the foundation for future service orientation.
In the IT Service Catalogue workstream, a clear target structure for ServiceNow was designed specifically for the financial industry. This structure served as the basis for populating the service catalogue and integrating individual client requirements through joint workshops.
In Service Asset & Configuration Management (SACM), the focus was on connecting all relevant source systems to ServiceNow to enable consistent CI provisioning. Process design and targeted training ensured organisational adoption.
For ICT Asset Management, dependencies between assets and services were systematically captured and mapped to ensure transparency and compliance.
Comprehensive test management, including interface and authorisation testing, enabled a controlled and smooth transition into production.


