
Aberdeen Group is a FTSE 100 UK-based wealth and investments group that includes a globally regulated asset management business. As a regulated financial services company subject to the Digital Operational Resilience Act (DORA), it must be able to evidence robust risk management practices with consistency, transparency, accountability, and end-to-end traceability.
The group already had frameworks, governance and a commitment to DORA in place. However, it needed tooling to keep pace with its strategy. Risk and resilience activity were previously distributed across systems, resulting in more effort to answer questions from the auditor or regulator than were optimal. Aberdeen determined that there was an opportunity to improve the former manual processes for evidence collection. Managing large sale operation and fragmentation risks was an important factor in pursuing a single platform.
Aberdeen processes c.2,000 risk events a year, maintains roughly 1,650 key controls, oversees about 1,200 third parties and runs 24 important business services globally. Close to 70 Key Risk Indicators were collated manually each month.
The company acted to consider how best to integrate risk management (formerly held in Shield), business continuity management (formerly in Riskonnect) and third-party risk (held in a SharePoint spreadsheet that required individual knowledge). Other tools and Office files were additionally required for further documentation.
The constraints were clear. Shield could not link a single control to more than one risk, which limited the maturity of the control framework. Key Risk Indicators sat separately from the risks they measured and had to be mapped by hand. Operational resilience reporting was rebuilt manually from offline sources. The third-party spreadsheet carried extensive embedded calculation and historical data that should have been retired, making maintenance challenging.
The thread running through all of it was simple: the systems required optimisation for speed, evidence collection and end to end visibility.
The approach: design the whole estate before build
Aberdeen already runs ServiceNow across the business, so the goal was to bring risk and resilience onto a shared enterprise platform. Before the build began, Pulsar ran workshops across the full risk and resilience estate, documenting each team’s processes, pain points and desired outcomes up front.
The reason was alignment. Every team designed against the same data model, including the teams whose build would not start for months. That meant phase one decisions did not need to be unpicked when phase two arrived.
Delivery ran in two phases. Phase one tackled the most complex parts of the build: risk management, controls, third-party risk and DORA-specific information registers and incident reporting. Phase two went live with operational resilience, business continuity management, disaster recovery, regulatory change and security assurance.
Across both phases, Pulsar delivered 2,097 story points. Phase two went live with no more than two P1 defects and very little surfacing in User Acceptance Testing.
Underneath the programme sits a standardised entity hierarchy aligned across risk, resilience and Aberdeen’s core data. That hierarchy allows all three lines of defence to work from one taxonomy and one structure instead of reconciling separate ones.
Knowledge transfer ran throughout rather than at the end. Change workshops sat alongside the build, Pulsar handed over at every go-live and the team stayed on for several weeks of embedded support afterwards to ensure Aberdeen was not left to work out the new platform alone.
The outcome: one platform, one view of risk
Aberdeen now operates a single consolidated enterprise platform, with a standardised entity hierarchy giving teams one central source to point at instead of six systems holding different versions of the truth. Risk owners don’t need to dig through other systems to understand how a risk connects to an entity or a control. Audit, second line and first line teams can read the same risk and control data, enabling them to avoid duplication between systems.
Third-party risk and DORA reporting now run from the same record
Supplier onboarding previously relied on email-and-spreadsheet exchanges with challenges around visibility of status, history or open issues. It now runs through a portal where that information sits in one place, supported by a full audit trail and far less chasing. Teams have no need to work out who changed a spreadsheet column or why because there is one record to review.
DORA extends the value of that same record into regulatory evidence. Third parties are linked to the services and critical functions they support, so concentration risk becomes visible rather than something that has to be chased manually. The Register of Information is built from live data rather than assembled by hand at reporting time. Major ICT-related incidents are captured, classified and tracked through initial, intermediate and final regulatory reports inside the same platform, allowing Aberdeen to evidence obligations from a single audit trail rather than reconstructing events afterwards.
Continuity and recovery are proved rather than assumed
Business impact assessments have been optimised and replaced with a structured assessment inside ServiceNow, tied to business processes and scored across seven impact categories on a consistent time basis, with MTPD and RTO derived automatically from that scoring. Two business areas assessing the same type of process can now land on the same answer, calculated the same way rather than judged differently depending on who runs it.
Continuity plans reach mobile devices and integrate with Everbridge, so the people who need to act can be reached and can respond even if corporate systems are unavailable.
Disaster recovery follows the same logic. DR plans sit against the CMDB and the real application landscape, so exercises test Aberdeen’s actual technology estate rather than an approximation of it. Exercises are scheduled, run and evidenced inside the platform instead of common practice of using email and tracked in a spreadsheet, turning DR testing into a managed programme. Once an exercise closes, the platform generates a full DR proving event report as a PDF, ready for regulatory review without anyone rebuilding it from meeting notes.
Pulsar took the time to understand our requirements and the outcomes we were trying to achieve, and led us on a journey throughout the entire project lifecycle. - Aberdeen Platform team
A foundation built to grow
The real prize is the foundation. A shared taxonomy, a single entity hierarchy and the core risk and resilience modules are live on one platform, making a more proactive risk posture possible. Concentration risk surfaces on its own. The Register of Information builds from live data. DR testing runs as a managed programme rather than an annual scramble. Aberdeen now has an improved view of Risk emergence and can take preventative action with more meaningful data to support these processes.
The pace of delivery also stands out. The full programme, from Global Design through phase two go-live, ran in eight months and covered risk, third-party risk, DORA, operational resilience, business continuity, disaster recovery, regulatory change and security assurance for a global regulated asset manager working across all three lines of defence.
The frameworks and governance were already there. What Aberdeen now has is the tooling to match them.
Want to achieve similar outcomes for your organisation? Get in touch with our Risk and Security Excellence Practice below.
Facing something similar?
Talk to the practitioners behind this work — we'll tell you honestly what we'd do.