Serverless Migration Patterns for Compliance-Critical Financial Applications on Microsoft Azure
DOI:
https://doi.org/10.63282/3050-922X.IJERET-V1I2P111Keywords:
Serverless Architecture, Azure Functions, Cloud Migration, Compliance Systems, Financial Applications, .NET Core, Azure Key Vault, Audit Trails, Risk Quantification, Application ModernizationAbstract
Migrating compliance-critical financial applications to serverless cloud architectures requires navigating a complex intersection of technical modernization, regulatory obligation, and operational continuity. This paper presents a systematic pattern catalog for migrating on-premises .NET financial applications to Azure serverless infrastructure, covering Azure Function App design, event-driven workflow decomposition, secret management via Azure Key Vault, and compliance-preserving logging and audit trail architectures. Each migration pattern is analyzed against regulatory requirements common in financial services environments including data residency, auditability, and access control mandates. Risk quantification methods are introduced for each migration phase, enabling organizations to bound and communicate migration risk to regulatory stakeholders. Validation is drawn from financial services modernization engagements across multiple enterprise environments.
References
[1] Scheuner, J., & Leitner, P. (2020). Function-as-a-service performance evaluation: A multivocal literature review. Journal of Systems and Software, 170, 110708.
[2] Yussupov, V., Breitenbücher, U., Leymann, F., & Müller, C. (2019, December). Facing the unplanned migration of serverless applications: A study on portability problems, solutions, and dead ends. In Proceedings of the 12th IEEE/ACM International Conference on Utility and Cloud Computing (pp. 273-283).
[3] Jangda, A., Pinckney, D., Brun, Y., & Guha, A. (2019). Formal foundations of serverless computing. Proceedings of the ACM on Programming Languages, 3(OOPSLA), 1-26.
[4] Rajan, R. A. P. (2018, December). Serverless architecture-a revolution in cloud computing. In 2018 Tenth International Conference on Advanced Computing (ICoAC) (pp. 88-93). IEEE.
[5] Shahrad, M., Balkind, J., & Wentzlaff, D. (2019, October). Architectural implications of function-as-a-service computing. In Proceedings of the 52nd annual IEEE/ACM international symposium on microarchitecture (pp. 1063-1075).
[6] Rajan, A. P. (2020). A review on serverless architectures-function as a service (FaaS) in cloud computing. TELKOMNIKA (Telecommunication Computing Electronics and Control), 18(1), 530-537.
[7] Chandy, K. M. (2016). Event driven architecture. In L. Liu & M. T. Özsu (Eds.), Encyclopedia of Database Systems (2nd ed., pp. 1–5). Springer. https://doi.org/10.1007/978-1-4899-7993-3_570-2
[8] Erik, S., & Emma, L. (2018). Real-time analytics with event-driven architectures: powering next-gen business intelligence. International Journal of Trend in Scientific Research and Development, 2(4), 3097-3111.
[9] Laszewski, T., Arora, K., Farr, E., & Zonooz, P. (2018). Cloud Native Architectures: Design high-availability and cost-effective applications for the cloud. Packt Publishing Ltd.
[10] Gilbert, J. (2018). Cloud Native Development Patterns and Best Practices: Practical architectural patterns for building modern, distributed cloud-native systems. Packt Publishing Ltd.
[11] Burns, B. (2018). Azure for architects: Design your cloud solutions with Microsoft Azure. Packt Publishing.
[12] Mills, A., & Haines, P. (2015). Essential strategies for financial services compliance. John Wiley & Sons.
[13] Baldini, I., Castro, P., Chang, K., Cheng, P., Fink, S., Ishakian, V., Mitchell, N., Muthusamy, V., Rabbah, R., Slominski, A., & Suter, P. (2017). Serverless computing: Current trends and open problems. In S. Chaudhary, G. Somani, & N. Buyya (Eds.), Research advances in cloud computing (pp. 1–20). Springer. https://doi.org/10.1007/978-981-10-5026-8_1
[14] Pearson, G. (2009). Financial services law and compliance in Australia. Cambridge University Press.
[15] Benantar, M. (2006). Access control systems: security, identity management and trust models. Boston, MA: Springer US.
[16] Negishi, Y., Hayashi, S., & Saeki, M. (2017, July). Establishing regulatory compliance in goal-oriented requirements analysis. In 2017 IEEE 19th Conference on Business Informatics (CBI) (Vol. 1, pp. 434-443). IEEE.
[17] Ingolfo, S., Siena, A., Mylopoulos, J., Susi, A., & Perini, A. (2013). Arguing regulatory compliance of software requirements. Data & Knowledge Engineering, 87, 279-296.
[18] Mohanty, S. (2018). Evaluation of serverless computing frameworks based on kubernetes.
[19] Moura, J., & Serrão, C. (2016). Security and privacy issues of big data. In Handbook of Research on Trends and Future Directions in Big Data and Web Intelligence (pp. 20–52). IGI Global. https://doi.org/10.4018/978-1-4666-8505-5.ch002
[20] Humphrey, C., Loft, A., & Woods, M. (2009). The global audit profession and the international financial architecture: Understanding regulatory relationships at a time of financial crisis. Accounting, organizations and society, 34(6-7), 810-825.
[21] Suh, B., & Han, I. (2003). The IS risk analysis based on a business model. Information & management, 41(2), 149-158.
[22] Haimes, Y. Y. (2011). Risk modeling, assessment, and management. John Wiley & Sons.
[23] Coleman, M. E., & Marks, H. M. (1999). Qualitative and quantitative risk assessment. Food Control, 10(4-5), 289-297.