Industries
Insurance and Takaful
Insurers sit on large volumes of sensitive personal and health data, run long-lived policy administration systems, and are modernising under commercial pressure — a combination that concentrates technology risk.
What we do for insurers
- IT general controls audit over policy administration, claims and the finance platform.
- Application control review across underwriting, claims and reinsurance processes.
- ERP and core system implementation review, pre and post go-live.
- Data protection assessment covering personal and health data holdings.
- Penetration testing of customer portals, agent platforms and internal infrastructure.
- Business continuity and disaster recovery audit.
- IT governance assessment supporting board and audit committee oversight.
Where the risk concentrates
Two areas dominate findings in this sector. The first is legacy policy administration — systems that have been extended for fifteen years, where the access model has accreted rather than been designed, and where nobody currently employed fully understands the interface layer.
The second is data. Insurers hold health information, financial detail and identity documents, frequently replicated into reporting environments, test systems and analytics platforms where the controls are materially weaker than in production. Test environments populated with unmasked production data remain one of the most common and most consequential findings we raise.
The control layer under policy administration and claims
Related services
Related regulatory frameworks
Tell us what you are actually being asked for
Describe the situation rather than the service. Working out the right scope is part of what we do, and it costs nothing to ask.
Request a proposal