Industry · Banking and insurance

Financial services event managementProof for every invitation.

Invite what compliance approves and prove what regulators ask, from client events to annual general meetings. AirLST keeps invitation, RSVP and attendance per guest, hosted in Germany.

  1. 1
    On-brand invitations

    One template; every branch invites against its allocation.

  2. 2
    Attendance per guest

    Invitation, RSVP and attendance sit on the guest with a timestamp.

  3. 3
    Back to the CRM

    RSVPs and attendance reach the contact in Salesforce through the connector.

Used by banks, insurers and asset managers
INGBausparkasse Schwäbisch HallDeutsche LeasingflatexDEGIROSparda-BankUniversal Investment
01Rules

What decides what is allowed at financial services events

Four rules every platform, invitation and meeting goes through. The first applies to US banks; the others apply to operations in the EU.

01

Third-party risk management (US)

The interagency guidance of the Federal Reserve, FDIC and OCC expects banks to manage third-party relationships from due diligence and contract to monitoring and termination. An event platform with customer data is one of them.

Source: Federal Register: interagency guidance, 2023
02

DORA Article 30 (EU)

For EU operations, the contract with an ICT provider must cover data processing locations, availability, access to and return of data, service levels and termination rights, and it goes into the register of information.

Source: DORA Art. 30 (springlex)
03

Inducements under MiFID II (EU)

Conference attendance and hospitality below a de minimis threshold are acceptable minor non-monetary benefits; their receipt has to be recorded.

Source: Section 6 WpDVerOV (German)
04

Annual general meetings (Germany)

A virtual AGM under German law requires video and audio, electronic voting and the right to speak by video; cooperatives with 1,500 members or more can hold a delegate assembly.

Source: Section 118a AktG (German)

These summaries are not legal advice; what counts are your compliance, vendor risk management and regulators. How AirLST processes data is described in the Trust Center.

02Roles

Who invites, who checks, and what each one needs

Compliance

Who was invited, and who attended?

Invitation, RSVP and attendance sit on the guest record with a timestamp and can be reviewed per event.

Guest list
Investor relations

How do I prove attendance at the AGM?

Registration with proxies, QR scan at the entrance and an attendance register to export for the minutes and the notary.

Annual general meetings
Sales and branches

How do 40 branches invite consistently?

One template in the corporate design, an allocation per branch, head office sees the total.

Invitation emails
Vendor risk management

What goes into the due diligence file?

Hosting in Germany on AWS, contractual service levels and the certifications of the hosting provider; the evidence is in the Trust Center.

Information security
04Product

What the industry requires and how AirLST delivers it

Standard means it is in the product and documented on the feature or solution page. Custom build means AirLST builds it for you in the project; scope and effort are part of the conversation.

RequirementStandardCustom buildMore
Invitation, RSVP, attendance per guestEach step sits on the guest record with a timestamp; shows and no-shows are added at the scan in real time.–Guest list
AGM with attendance registerNotice with deadline, registration with proxies, QR scan at the entrance, attendance register as an export.–Annual general meetings
Online votingIts own voting for general meetings with for, against and abstain.–Annual general meetings
Allocations per branchTemplate set up centrally in the corporate design, each branch invites against its allocation.–Invitation emails
Salesforce and HubSpot connectionREST API and connectors for Salesforce and HubSpot; SAP and Microsoft Dynamics can be connected.–Integrations
DORA contract annexA contract annex with the Article 30 DORA terms and the data for your register of information is prepared with you in the project.–Information security
Compliance approval before sendingAn approval step with a value threshold before an invitation goes out is a custom build by AirLST.–Custom development
Hospitality value per guestThe value per invitation and a running total per recipient over the year are a custom build by AirLST.–Custom development
A login for each branchIf each branch should see only its own guests, AirLST builds that as a custom build.–Custom development
Single sign-onSign-in through your identity provider is a custom build through our integration services.–Integration services

Security and data protection

  • TISAX-assessed

    AirLST has been assessed under TISAX, the information security standard of the automotive industry.

    TISAX at AirLST
  • Hosted in Germany

    The platform runs on Amazon Web Services in Germany. The AWS infrastructure holds ISO/IEC 27001, SOC 2 and BSI C5; these are certifications of our hosting provider, not of AirLST.

    Data hosting
  • GDPR and DPA

    Processing follows the GDPR, with a data processing agreement; the current list of subprocessors is provided with it.

    GDPR
  • Signed at the guest

    Consents and NDAs are signed digitally and stored with the guest record; the entrance sees at the scan whether the signature is there.

    Event access control
Paid eventsStripeMolliePayPal

Tickets and fees are paid in the registration form through Stripe, Mollie or PayPal. Revenue goes straight to your account; card data stays with the provider.

Event ticketing
05Setup

How banks and insurers typically set up AirLST

  1. 01

    Central template, local invitations

    Invitation and registration page in the corporate design; branches invite against their allocation.

  2. 02

    Required fields per event

    Client number, shareholder or member number, proxy as registration fields.

  3. 03

    Admission with attendance

    QR scan at the entrance, attendance register in real time and as an export.

  4. 04

    Voting at meetings

    Online voting with for, against and abstain.

  5. 05

    Attendance into the CRM

    Status per guest through the Salesforce or HubSpot connector.

The event platform is a third party

US banking regulators expect a bank to manage the risk of every third-party relationship, from due diligence to termination (Federal Register). In the EU, DORA has applied since January 17, 2025, and banks and insurers keep a register of their ICT providers for the supervisor (BaFin, German). That turns the choice of event software into a question for vendor risk and IT, not just marketing.

AGMs return to the room

According to the German shareholder association DSW, 65 percent of the companies it studied held their 2025 AGM in person and 77 index companies met virtually; only 69 percent of the virtual meetings ran without disruption (DSW AGM report 2025, German PDF). In person means admission at the door, an attendance register, proxies and voting, all on record for the minutes and the notary.

The attendance register is not a by-product. It is the record.

Every invitation is a benefit

Client evening, seminar or suite: for the firm, the invitation is a benefit that has to be recorded under MiFID II rules in the EU (section 6 WpDVerOV, German). AirLST keeps who was invited and who attended per guest; value thresholds and approvals we build in the project through custom development.

08FAQ

Frequently asked questions about financial services event management

Is an event platform a third-party relationship for a US bank?

Yes, if it processes customer data on the bank’s behalf. The 2023 interagency guidance of the Federal Reserve, FDIC and OCC expects risk management across the life cycle of third-party relationships: planning, due diligence, contract negotiation, ongoing monitoring and termination (Federal Register). AirLST hosts in Germany, agrees service levels in the contract and provides the certifications of its hosting provider AWS.

What has to be in a DORA contract with an event platform?

For banks and insurers operating in the EU, an event platform that processes customer data is an ICT third-party service provider. Article 30(2) DORA lists mandatory contract terms, including the locations of data processing, availability, access to and return of data, service levels and termination rights (DORA Art. 30). A contract annex with these terms is something we prepare with you in the project.

Can a bank in the EU invite clients to events?

Within limits. Under the German implementation of MiFID II, attending conferences and seminars and hospitality below a de minimis threshold count as acceptable minor non-monetary benefits, and their receipt has to be recorded (section 6 WpDVerOV, German). AirLST records who was invited, who confirmed and who attended per guest; tracking meal value per guest is a custom build.

Can AirLST run an annual general meeting?

Yes: notice with deadline, registration with proxies, QR scan at the entrance, an attendance register you can export for the minutes and the notary, and its own online voting with for, against and abstain; see annual general meetings. For a virtual meeting with video and audio you work with your streaming provider; we connect it in the project.

Can branches invite their own clients?

Yes. The template in your corporate design is set up centrally; each branch invites its clients against its own allocation, and head office sees the total. If each branch should have its own login that shows only its guests, AirLST builds that as a custom build.

How does a financial services firm run many events a year?

With one design model for all landing pages and a survey after every event. Interhyp runs 30 recurring events with 4,000 attendees this way, described in the Interhyp case study.
Events made easy

Every invitation on record. Every meeting documented.

In 15 minutes we show you how invitation, attendance and voting work together in AirLST, and what we build for DORA and compliance approvals in the project.