Skip to content

Risk management

6.8.2026

Digia’s risks are classified as strategic, financial, operational, and sustainability risks. The Audit Committee of the Board of Directors is responsible for supervising the implementation of risk management and assessing its effectiveness. Monitoring focuses on risks of material significance to the company that are classified as high risk. Digia’s Group Management Team is responsible for the appropriateness of risk management and overseeing operational activities. The owner of risk management is responsible for reporting on risks and their correct assessment. Digia’s risk management process is supported by centralized risk management software.

Changes in the risk status are reported to the Audit Committee twice a year, and the Group Management Team monitors the risk status at its regular meetings. These reports cover the risk status, the impacts of significant risks and measures used to manage them, and the monitoring of objectives, including the specified indicators.

The company’s strategic and financial risks relate to increasing competition through, for example, prices and contractual terms, and to potential significant changes in the company’s operating environment and service areas. Geopolitics, general economic trends, higher interest rates, and changes in customers’ operating environment and financial position may have an unfavorable impact on the company’s business, financial position, and result through slower decision-making and the postponement or cancellation of IT investments.

Implementing the growth strategy places demands on both the organization and its management. The company’s ability to recruit, maintain, and develop the correct competence – and also to correctly time the offering to meet demand – will play a vital role. In line with its strategy, Digia is also seeking growth through acquisitions. However, Digia cannot be certain of locating suitable companies for acquisition or of successfully integrating them.

Operational and cyclical risks largely involve short-term demand. If demand sees a sharp fall, price levels might also decline. Pricing models in the service business help to balance out business cycles. When costs increase, it is not certain how quickly and to what extent the rise in costs will be passed on to market prices.

Advances in AI are transforming the business models of software development and the IT services industry, which could have a negative impact on the company’s net sales. On the other hand, this development also offers the company new business opportunities.

Major customer projects – and fixed-price projects in particular – involve both business opportunities and risks. As customer projects increase in size, the risks associated with profitability management also grow, and there is a greater need to manage extensive contract and delivery packages. Large customer projects typically involve delivery-related sanctions. At the same time, the risks associated with accounts receivable are also rising.

Data security and protection risks comprise a significant risk area in the company’s business operations. Organizations have more and more information that is critical to their operations. Threats to data security and protection have risen significantly in recent years. The increasing use of artificial intelligence also poses potential risks, and its effective and safe utilization requires organizations to adopt updated operating practices. Data security and protection risks mainly concern technology and people. Significant risk factors also include risks posed by high-security projects and subcontracting chains. Due to the nature of its operations, the company may also be a target of hostile influence.

The company identifies, manages, and prevents both internal and external threats. The company implements a regular ISO 27001-certified risk management process based on best practices in handling data security and protection risks. Risks are identified and their impact and significance are analyzed. The risk level is reduced with appropriate measures where possible. Operational response and the handling of potential threats have been planned, rehearsed, and tested in practice. The company's employees are continuously trained, and data security and protection issues are actively communicated within the company and, if necessary, also to partners and customers. The company works in close cooperation with a variety of data security and protection authorities and networks. Physical security and personnel safety issues are managed using mechanisms similar to those employed in data security and data protection.

Sustainability risks consist of environmental, social, and governance risks. Environmental risks in office work are quite small. Global supply chains for IT equipment and services may be disrupted as a consequence of geopolitical and climate threats. The potential risks related to social responsibility that are monitored include experiences of overwork, occupational wellbeing, discrimination, and unequal treatment. Potential human rights risks in the subcontracting chain have been analyzed, and their probability is actively monitored. Human rights risks are also taken into account when selecting new subcontracting partners. Administrative risks primarily concern the company's legal and regulatory compliance, ethical operations as well as data security and protection.

Increasing regulation may also adversely impact the development of Digia’s net sales and cost level.