10.04.2025
Reading time: 3-4 minutes

Knowledge crisis in financial software

Software Improvement Group

In this article​

Summary

Financial institutions depend on complex software landscapes to process transactions, meet regulatory obligations and deliver reliable services. Yet critical knowledge about these systems is often concentrated in a small number of developers, architects or external suppliers. This knowledge crisis makes software harder to maintain, change and govern when key people are unavailable or leave.

For technology leaders, the issue is not only a talent challenge. It is a software portfolio risk that affects delivery speed, operational resilience, security and the ability to modernize core systems responsibly. For contributing factors and mitigation strategies, see our analysis of legacy technology in financial services.

Mockup of the finance signals report

What is the knowledge crisis in financial software?

A knowledge crisis occurs when too few people understand how a software system works well enough to safely maintain or modify it. In financial software, that knowledge can include application architecture, business rules, interfaces, deployment processes, data flows, dependencies and the rationale behind historical design decisions.

These systems frequently support regulated and business-critical processes. When knowledge is held by only one or two contributors, routine work can become dependent on their availability. Teams may delay changes because they cannot confidently assess the impact, while new developers require more time to become productive.

SIG tracks knowledge distribution and component freshness. In SIG's Finance Signals 2025 report, these were presented together as a knowledge rating. The properties consider:

  • Knowledge distribution: whether significant code contributions are spread across enough authors rather than concentrated with a few individuals.
  • Component freshness: whether software components are actively maintained rather than left unchanged for long periods.

According to SIG's 2025 Financial Signals benchmark, 66% of FSI systems assessed by SIG fell below its recommended knowledge-distribution rating. This indicates that knowledge concentration is a widespread concern across the financial software portfolios assessed by SIG.

Why concentrated software knowledge creates business risk

Knowledge concentration is often invisible until an incident, major change or employee departure exposes it. A system may appear stable, but its maintainability can deteriorate when only a limited group can diagnose failures, review changes or explain dependencies.

Slower change and modernization

Modernization initiatives require teams to understand the current state of applications before they can safely refactor, replace or integrate them. If architecture and code knowledge are concentrated, teams spend longer validating assumptions and waiting for the right specialists. This slows delivery and makes transformation programmes more difficult to prioritize. Explore legacy application modernization options to surface hidden knowledge and de-risk change.

The image features a graphic with two large, overlapping squares: one red and the other orange. Each square contains a percentage figure and accompanying text. The red square is on the left with the text "66% in FSI below recommendation," and the orange square is on the right with "60% in non-FSI." Above the squares, there is a "Knowledge rating" section with a row of five stars, two of which are blue, and one is half blue, indicating a 2.5 out of 5 rating.
Architecture characteristics are defined by SIG’s Architecture Quality Framework. The SIG Architecture Quality Model provides insight into the ability of an application to evolve as business needs change. The knowledge rating is one of the five aspects of Software Improvement Group’s Architecture Model and consists of two properties: “Component freshness” (which measures the distribution of recent code churn across system components as regular maintenance occurs) and “Knowledge distribution” (measured as the number of authors with significant contributions to a component per KLOC—thousand lines of code). 

Higher operational and continuity risk

During a production incident, recovery depends on timely access to accurate technical knowledge. If the people who understand a critical component are unavailable, investigation and remediation can take longer. In financial environments, extended disruption can affect customers, operations and regulatory responsibilities.

The image is a conceptual diagram with three main elements, each represented by circles. On the left, an orange circle labeled "Limited knowledge sharing" contains orange stick figures using laptops, connected by bidirectional arrows, symbolizing restricted exchange. In the center, a large gradient circle labeled "Shared knowledge" features bidirectional arrows connecting blue and purple stick figures with laptops, indicating open collaboration. On the right, a blue circle labeled "Knowledge monopoly" shows a blue stick figure with a laptop and a small exclamation mark inside an orange circle, highlighting limited access. The flow of information is illustrated by arrows pointing towards the central circle.

More expensive maintenance

New engineers can maintain unfamiliar software, but undocumented complexity and unclear ownership increase the effort required to make changes safely. Over time, this can turn routine maintenance into specialist work, increasing dependency on individual contributors and limiting development capacity.

The image features two groups of circles, illustrating the difference between consistent and inconsistent system updates. On the left, "Consistent system updates" is shown with six circles filled with a gradient of blue and light blue, each encircled by a green border. The circles vary in size, with the largest in the center. On the right, "Inconsistent system updates" consists of six circles with varying shades of blue, some with orange and red borders. Two smaller circles feature red exclamation mark icons, indicating issues. Below is a gradient bar labeled "Frequency of system updates," ranging from dark to light blue, symbolizing update frequency.

Weaker governance across the portfolio

Large financial organizations rarely have only one application. Knowledge risks can accumulate across customer platforms, core systems, reporting applications and internal tools. Without portfolio-level visibility, leaders may not know which systems have fragile knowledge distribution or aging components until a business-critical issue arises. Practical patterns to institutionalize system knowledge are summarized in the FSI IT Governance Playbook.

2025 State of IT in Financial Services report

Exclusive insights on AI, security and reliability delivered to your mailbox

Read our methodology

This field is for validation purposes and should be left unchanged.

Watch Core in action

This field is for validation purposes and should be left unchanged.

Watch Axis in action

This field is for validation purposes and should be left unchanged.

This field is for validation purposes and should be left unchanged.
Name*
Privacy*

This field is for validation purposes and should be left unchanged.
Name*
What type of partnership are you interested in?*
Privacy*

Register for access to Summer Sessions

This field is for validation purposes and should be left unchanged.
Name*
Privacy*