
T-NEX Banking Platform
One banking platform for controlling, reporting, compliance, risk, PPM and fraud detection. Shared data model, AI at the core, configurable for your institution.
Learn moreWe make the intended application's data flows, interfaces and model access visible. Together with information security, the CISO and IT, we define suitable access and responsibilities. Use can then be assessed against the actual system environment.
Platform principle; the specific scope is agreed for each project.
For information security leaders and the functions involved in ICT provider assessment.
DORA connects ICT risk management, incident reporting, resilience testing and third-party risks. Technical assessment of an application therefore considers its full data and operating flow. Calling a role ISB or CISO does not by itself define its internal decision rights.
| Assessment area | Required outcome | Functions to involve |
|---|---|---|
| Data and interfaces | Data flow with sources, recipients and access countries | Business team, IT, data protection and information security |
| Permissions and AI | Permitted data access and assistant actions | Business owner and system administration |
| Operations and incidents | Operator, contacts, recovery and handover | Operations, provider management and business owner |
The T-NEX platform manages roles and permissions for functions and reports. Implementation checks what each user may read, edit or approve. Testing also covers direct function calls and the underlying objects.
One useful case is moving a person from editing to read access. Required views and prohibited changes are then checked. Technical accounts and support access receive their own defined tasks and access paths.
Generating reporting logic from a schema processes different information from analysing document contents. For each function, we therefore identify the provider, model connection, information scope and permitted system actions.
AI connections and permitted assistant functions are configured for your environment. We also assess data flows and access by support teams and model providers. The hosting location is one part of that assessment.
Before approval, the contracting entity, participating units, access countries and services are brought together. Data protection documents such as a DPA and technical and organisational measures, plus transfer arrangements where relevant, need to match the actual setup. Their project-specific provision and review are agreed during the engagement.
Technical functions, security evidence and operational services are assembled for the specific engagement. This establishes the requirements your installation needs to meet and who is responsible.
Together, we determine which findings must be resolved before go-live and who accepts the results.
That does not follow from hosting location. Development, support and AI processing have separate data flows. Access countries and participants are considered for the specific engagement.
The public page provides technical evidence and topics for provider assessment. Contract and data protection documents are matched to the actual service and agreed during the engagement.
This page concerns assessing a T-NEX business application. It does not promise a complete register of information, a security operations centre or an incident reporting platform as a ready-made product.

One banking platform for controlling, reporting, compliance, risk, PPM and fraud detection. Shared data model, AI at the core, configurable for your institution.
Learn moreEntities, international team locations, data access and operational responsibilities: concrete topics for assessing a proposed engagement with T-NEX.
Learn moreFunctions, manual versions and assessment cases for T-NEX Controlling, Compliance, PPM and Fraud Detection, with an editable procurement overview.
Learn moreT-NEX plans hosting and operations for institutional software, with agreed operating tasks, suitable resources and clear ownership of applications and infrastructure.
Explore serviceBring a concrete task. Together, we will define what the application needs to do.
Define the technical assessment scope