As European banking regulations like DORA and the EBA’s third-party risk guidelines make supplier oversight an explicit board duty, leading financial institutions are shifting away from fragmented point solutions. Nordea, a major Nordic financial services group serving over 9 million private customers and 500,000 corporate clients, selected Zycus to drive its end-to-end S2C transformation on the Merlin Agentic Platform.
By uniting native Intake, sourcing, contract lifecycle management (CLM), supplier management, and supplier risk into a single architecture, Nordea is bridging the gap between disparate data silos without disrupting core ERP or payment systems. In this article, we examine what Nordea’s S2C transformation covers, why European banks are consolidating supplier management into one connected view, and how agentic procurement helps satisfy strict regulatory demands.
Key Takeaways
- The news: Nordea, the Nordic financial services group headquartered in Helsinki, has selected Zycus as its Source-to-Contract (S2C) platform provider (announced 22 September 2026).
- The scope: sourcing, contract lifecycle management (CLM), supplier management and supplier risk, all on the Merlin Agentic Platform, which includes native Intake.
- The why: European rules now treat supplier oversight as a board duty. The EBA’s new third-party risk guidelines (September 2026) cover the whole supplier lifecycle, from due diligence to exit.
- The pressure: the ECB reports that 82% of banks’ critical outsourced functions are difficult or impossible to replace.
- What stays put: the ERP and the payment layer. The platform adds one connected view of contracts, suppliers and sourcing events on top of them.
One question, four systems
Picture a supervisor asking a bank’s procurement team a simple question. Which suppliers support our critical services, and where are the contracts that give us the right to audit them?
The answer exists. It just lives in four places. The supplier list sits in one tool, the contracts in a shared drive, the risk screening in another application, and the story of how each supplier was chosen in someone’s inbox. Pulling it together takes days, and nobody is fully sure the final spreadsheet is complete.
This is the everyday reality behind a lot of banking procurement, and it is exactly the gap Nordea is closing. On 22 September 2026, Zycus announced that Nordea has selected it as its Source-to-Contract platform provider. Nordea will implement the Merlin Agentic Platform as part of its procurement transformation.
This blog explains what that selection covers, why European banks are choosing the full span over a single point tool, and what deliberately stays untouched.
What Did Nordea Select?
Nordea selected four capabilities on one platform: sourcing, contract lifecycle management, supplier management and supplier risk. They run on the Merlin Agentic Platform, which brings native Intake and the Source-to-Contract suite together in a single architecture, with Agentic AI embedded in every process.
The scale matters here. Nordea has served customers for more than 200 years. Today it serves about 9 million private customers and over 500,000 active corporate customers across Finland, Sweden, Denmark and Norway. A bank of that size runs on thousands of supplier relationships, and each one has to be chosen, contracted, watched and, one day, exited with care.
| Capability | What it does, in plain words | Why a bank cares |
| Intake (native to the platform) | Gives every business request one front door and guides it to the right path | Every supplier engagement starts on the record, not in an email |
| Sourcing | Runs tenders and supplier selection in one workspace | Shows how and why each supplier was chosen |
| Contract lifecycle management (CLM) | Drafts, approves, stores and tracks contracts and their obligations | Audit rights, exit terms and obligations are easy to find and follow |
| Supplier management | Onboards suppliers and keeps one profile for each | One source of truth for who the bank works with |
| Supplier risk | Screens and monitors suppliers for risk over time | Problems show up early, not at the next annual review |
Callout: None of these capabilities is new on its own. What is different is that they run on a single architecture, so a supplier, its contract and the sourcing event behind it stay linked.
Why Are European Banks Buying the Full Span, Not a Point Tool?
Because supplier oversight has moved from the procurement desk to the boardroom. As the Nordea press release puts it, requirements for supplier oversight, auditability and operational resilience continue to increase. Three European developments explain why.
- DORA made supplier risk a board responsibility. The Digital Operational Resilience Act has applied since 17 January 2025. It makes a bank’s management body responsible for ICT risk, including a strategy for risk from ICT third parties. Banks must keep a register of every contract with an ICT service provider, and those contracts must include rights of access, inspection and audit, plus clear exit strategies (DORA, Articles 5, 28 and 30).
- The EBA widened the lens to every third party. On 18 September 2026, the European Banking Authority published its final Guidelines on third-party risk management. They replace the 2019 outsourcing guidelines and cover the full life of a supplier arrangement: risk assessment and due diligence, contracting, subcontracting, monitoring, documentation and exit. Banks get a two-year implementation period. The final report is clear that using a provider cannot result in the delegation of the management body’s responsibilities.
- Supervisors keep flagging the gap. In its supervisory priorities for 2026 to 2028, ECB Banking Supervision notes that operational and ICT risk still receive “the worst average scores in the SREP”, its annual review of each bank. It plans on-site inspections focused on third-party risk management.
By the numbers (ECB, outsourcing register data)
- 82% of banks’ critical outsourced functions are difficult or impossible to replace
- 95% of those could not easily be brought back in-house
- 67% of outsourcing contracts involve further subcontractors
- 27% of critical ICT services come from providers outside the EU
- Source: ECB Supervision Newsletter, February 2025
Here is the practical problem. The rules follow a supplier from the first request to the final exit. A point tool covers one stage of that journey. When sourcing, contracts, supplier profiles and risk checks live in separate systems, the bank has to rebuild the evidence by hand every time a supervisor or auditor asks.

Figure 1: Five core stages of the supplier lifecycle in the EBA guidelines, and where each one is handled on a single platform.
Keeping that evidence clean is harder than it sounds. When the European Supervisory Authorities ran a dry run of the DORA register of information with nearly 1,000 financial firms, only 6.5% of the registers passed every data quality check.
Callout: Regulators now look at the supplier lifecycle as one story. Banks are choosing platforms that can tell it as one story too.
The Three Things a Banking Group Needs One View Of
Strip away the terminology and a banking group needs clear, connected answers about three things: its contracts, its suppliers and its sourcing events.

Figure 2: Requests enter through one front door, and the platform keeps suppliers, contracts and sourcing events linked in one record.
Suppliers: who do we depend on? Every supplier should have one profile, not five versions across teams and countries. That profile holds onboarding checks, certificates, risk screening and performance. When the same data feeds every business unit, the bank can see its true exposure to a single provider.
Contracts: what did we agree? DORA and the EBA guidelines are, in large part, rules about what a contract must say and whether the bank can prove it. Audit rights, exit terms, notice periods and service levels need to be findable in minutes. Obligations need owners and reminders, so a commitment made at signing is still tracked three years later.
Sourcing events: how was this supplier chosen? Due diligence is the first stage of the EBA lifecycle. The record of who was invited, how bids were scored and which risks were checked before the award is the bank’s evidence that the choice was sound. When the risk check happens inside the sourcing event, it is part of the record by default.
The value is in the links between the three. A contract points back to the sourcing event that produced it, and forward to the supplier profile that must be monitored. That chain is what turns a request for evidence from a week of spreadsheet work into a report.
Callout: One view does not mean one team does everything. It means every team works from the same record.
What Stays Untouched: the ERP and the Payment Layer
A Source-to-Contract programme like this one does not rip out a bank’s core systems. The ERP (Enterprise Resource Planning system, such as SAP) stays the financial system of record. The payment layer, where money actually moves, stays exactly where it is.
Figure 3: The capabilities Nordea selected form a new layer above the ERP and the payment layer, connected to them rather than replacing them.
That is a deliberate design choice, and it matters for a bank for two reasons.
Lower risk to critical operations. Payment systems and the general ledger are among the most tightly controlled systems a bank runs. Leaving them alone keeps the transformation away from the parts of the bank where a disruption would be felt by customers.
A faster start. The capabilities Nordea selected (sourcing, CLM, supplier management and supplier risk) sit upstream of both layers. They decide who the bank buys from and on what terms. That work can be modernised without waiting for a wider finance system change.
The platform connects to the systems around it rather than replacing them. Zycus supports standard integrations with ERPs such as SAP and Oracle, so supplier and contract data can flow to where finance needs it.
What This Signals for Banking Procurement
Nordea’s choice reflects a wider shift among European banks, and Zycus Founder and CEO Aatish Dedhia framed it simply in the announcement:
“European banks are modernising procurement to achieve greater consistency and oversight across large supplier bases.”
Aatish Dedhia, Founder and CEO, Zycus
Consistency and oversight are the two words to hold on to. Consistency means every request, tender and contract follows the same path, whichever country or business unit it starts in. Oversight means leaders can see that path end to end, with the evidence attached.
This is also where Agentic AI earns its place. On the Merlin Agentic Platform, Agentic AI is embedded in every process rather than bolted on at the end. Merlin Intake guides each request from the moment it is raised, so the record starts clean. The aim is Autonomous Procurement: work that moves toward an outcome, with people stepping in where judgement is needed.
Three questions for your own set-up
If you lead procurement or third-party risk at a bank, try these:
- If a supervisor asked for every critical supplier, its contract and its exit plan today, how long would your team take to answer?
- Does your risk check happen before a supplier is selected, or after the contract is signed?
- How many systems hold a version of the same supplier record?
If the honest answers are “days”, “after” and “more than one”, the gap Nordea is closing is probably yours too.
A modern S2C transformation is not about replacing core general ledgers or payment gateways, it is about establishing a single connected record that links every supplier, contract, and sourcing event from initial request through to exit. By embedding Agentic AI into a unified architecture, banks can ensure complete regulatory compliance, eliminate manual audit preparation, and maintain total oversight across their entire supplier network. As third-party risk remains a primary focus for financial supervisors, having a transparent, end-to-end view of supplier engagements is essential for long-term operational resilience
Book a demo and we will walk you through the same set-up Nordea selected, and how it could transform Source-to-Contract (S2C) for your company.
Checkout more:
Frequently Asked Questions
Q1. What is Source-to-Contract (S2C)?
Source-to-Contract covers the first half of the buying journey: taking in a request, choosing a supplier, agreeing and managing the contract, and managing the supplier and its risk over time. It stops before ordering, invoicing and payment. An S2C platform keeps those steps in one place, so data from one stage carries into the next instead of being retyped.
Q2. What exactly did Nordea select from Zycus?
Nordea selected Zycus for its Source-to-Contract transformation and will implement the Merlin Agentic Platform. The scope spans sourcing, contract lifecycle management, supplier management and supplier risk, on a platform with native Intake.
Q3. Why do European banks need a platform rather than separate tools?
European rules such as DORA and the EBA’s third-party risk guidelines follow a supplier across its whole life, from due diligence to exit. Separate tools each hold part of that story. A single platform keeps the sourcing record, contract and supplier profile linked, which makes oversight and audits far simpler.
Q4. Does a Source-to-Contract transformation replace the bank’s ERP or payment systems?
No. The ERP remains the financial system of record, and the payment layer stays where it is. The Source-to-Contract platform works upstream of both and connects to them.
Q5. How does the Merlin Agentic Platform support banks with supplier oversight?
It brings intake, sourcing, contracts, supplier management and supplier risk together in one architecture, with Agentic AI embedded in every process. Zycus works with banking and financial services organisations across Europe and globally. See the banking and financial services page for more.
Sources
- Zycus, Nordea and Zycus press release, 22 September 2026
- EUR-Lex, Regulation (EU) 2022/2554, Digital Operational Resilience Act
- European Banking Authority, Final Guidelines on third-party risk management, 18 September 2026, and the final report
- ECB Banking Supervision, Supervisory priorities 2026 to 2028, November 2025
- ECB Banking Supervision, Outsourcing trends in the banking sector, Supervision Newsletter, February 2025
- ESMA for the European Supervisory Authorities, Dry run exercise on registers of information under DORA, December 2024





















































