EspañolCatalà
Valdrent/Automation/Insurance
Insurance companies and intermediaries · Supervised by the SSF

The claim file,
complete from first notice.

We build the processes that surround your policy administration system: underwriting, issuance, first notice of loss, the policyholder complaint, the intermediary commission and the information you file with the supervisor. Data is captured where the work happens, with the clock in plain sight, so the evidence exists before anyone asks for it.

Request the vendor qualification dossier
Interface concept
Claim file Case XXXXXX · Property and casualty
Internal resolution deadline
2 days left
Required documentation
1 of 6 missing

The file is incomplete. Closing is not enabled.

Close and notify Disabled

The clock runs for everyone who sees the case, not only for whoever remembers it.
Where traceability is lost today

Four problems that belong
to the process, not the insurer.

The file lives in three places

Part in the policy system, part in the adjuster’s inbox and part in a shared folder. Reconstructing what was resolved and on what grounds takes hours, and the result is a narrative, not a record.

The deadline emits no signal

A complaint parked while a document is awaited says nothing until it has already lapsed. Control depends on somebody opening a spreadsheet on the right day.

The same data is keyed twice and three times

From form to system, from system to spreadsheet, from spreadsheet to the filing template. Every rekeying is an opportunity for a gap between what happened and what is reported.

The distribution network is controlled by hand

Credential validity, settled commissions, production by channel and registered mass distributors are verified against lists that start ageing the day they are compiled.

Scope

What we build
and what we leave untouched.

Digitalizing an insurer’s processes is not replacing its policy administration system. The technical core, the accounting system and the document manager stay where they are, and the work integrates with them.

In scope

  • Data capture at the point where the work happens, including the adjuster’s field work
  • Guided execution of the process, with sequence control and verification of prior requirements
  • Deadline monitoring with automatic escalation and per case visibility
  • Dual control and segregation of duties enforced by the system
  • A single file per policy, per claim and per complaint, with all associated documentation
  • A complete audit trail, with version, author and reason for every change
  • Validity control over credentials and registration across the distribution network
  • Integration with the existing policy system, accounting system and document manager
  • Generation of regulatory filing templates from the record itself, without prior transcription

Out of scope

  • The policy administration system and the accounting system are not replaced
  • Technical notes, rates and actuarial calculation are not modified
  • No underwriting or coverage decision is taken by algorithm
  • The judgment of the adjuster, the underwriter and the committee is not replaced
  • No interface automation component sits on the critical path of a supervised record
Processes we digitalize

Where the system intervenes,
process by process.

We do not deliver a closed product with these processes preconfigured. They are examples of the kind of process we digitalize, and every implementation is designed on your entity’s real lines of business, procedures and formats.

Regulatory mapping · Risk, security and continuity

What the regulation requires on record,
and the control that produces it.

An insurance company is subject to the same body of technical norms on risk management, information security and business continuity as the rest of the supervised financial system. This is the mapping between what those norms require to be sustained and the control that produces it.

Mapping of topics from the technical norms applicable to insurance companies to the implemented control. Working draft, pending review by a practising compliance officer or risk manager.
Norm Requirement Implemented control
NRP-20 Integrated risk management sustained by a formal methodology, with enough information for the board to decide and for the supervisor to review. Structured recording of the event and the control, traceable from the source data to the report presented, with no later reconstruction.
NRP-42 Operational risk management over processes, people, technology, information and external events, with systematic identification and recording of events. Capture of the event as it happens, classification by factor and effect, evidence of treatment, and a dashboard by process and responsible unit.
NRP-17 Corporate governance with defined responsibilities and a record of what each body knew and approved. Approval authority lives in the role, is enforced at the point of decision and leaves a record of who approved, when, and on which version of the file.
NRP-23 Information security management, with formal control over granting, review and revocation of access. Role based access control against the existing corporate directory, with periodic review exportable as evidence. No parallel identity repository is created.
NRP-24 A business continuity management system, sustained by impact analysis and documented testing. Documented fallback procedure for the digitalized process, scheduled backup, and restoration testing with an archived report.
NRP-36 Management of money laundering, terrorist financing and proliferation financing risk, with due diligence and retention of the evidence. Integration with the existing prevention system, with the result of the check and its date attached to the policy or claim file.

The complete mapping, referenced to your risk matrix and your procedures in force, is delivered as a formal assessment within the evidence file.

Regulatory mapping · Insurance operations

The regulation specific to insurance,
and the data that sustains it.

Mapping of topics from the technical norms specific to insurance activity to the implemented control. Working draft, pending review by a practising compliance officer or risk manager.
Norm Requirement Implemented control
NRP-39 Filing of insurance company information for the preparation of insurance activity statistics. The submission is generated from the same record that operated issuance and claims, with reconciliation beforehand and proof of filing archived.
NRP-70 Filing of information from the accounting system of insurance companies. Verified interface against the accounting system, with discrepancy logging and an audit log for every submission. Every reported figure traces back to the operation that produced it.
NCS-011 Constitution of the technical reserves that must be maintained. The data feeding the calculation is captured at source, with notice date, estimate, movements and closing versioned and auditable.
NRP-66 Deposit of insurance policy models. Version control over the deposited model, with electronic approval and issuance blocked on any version not in force.
NRP-67 Registration of entities that distribute insurance policies on a mass basis. Registration of the distributor with validity, assigned portfolio and training record. Distribution is blocked once validity has expired.
NPS4-11 Authorization and registration of insurance intermediaries. Credential validity verified before portfolio assignment and before commission settlement, with advance warning of expiry.
NCM-03 Transparency and disclosure of information to the user. Proof of the information delivered to the user, with document version, channel, date and acknowledgement, retrievable from the file.

Pension related lines and operations with the Salvadoran social security institute add their own filing requirements. The design starts from the most demanding requirement applicable to your portfolio.

The clock

Deadlines the system watches,
not somebody’s memory.

Many of an insurer’s obligations are not met well or badly: they are met within the deadline or breached. A process that runs against a clock needs the clock to be part of the system.

The claim, from first notice

The clock starts with the notice, not with the file being opened in the system. Every request for documentation to the policyholder is recorded with its date, because the count depends on it.

The policyholder complaint

The case shows time consumed and time remaining against the deadline defined in your procedure, and escalates when it is at risk, not once it has lapsed.

Periodic filing

The supervisor filing calendar is managed inside the system, with an assigned owner, configured lead time and proof of submission archived.

Validity that expires

Intermediary credentials, distributor registrations, policy models and reinsurance treaties give warning before they expire, not after.

Sovereignty over data and system

Your supervised file
lives where the entity decides.

A policy file contains personal data and, in personal lines, health data. It should not live in a vendor’s infrastructure, nor depend on that vendor continuing to exist.

Data does not leave your environment

The system is deployed inside your infrastructure. We do not host information about your policyholders or credentials to your systems outside it.

Access is ephemeral, minimal and audited

Our access to your environment is governed by the Sovereign Access Protocol: least privilege, audited channel, no retention, revocable unilaterally by you at any time.

Sovereign Access Protocol →

Components communicate through interfaces

Each layer is replaceable without rebuilding the others. If the policy system changes tomorrow, the file, the traceability and the audit trail survive.

Continuity does not depend on us

Complete technical documentation delivered, accessible version control, and source code escrow contractable as a clause of the agreement. We hand you a system you own.

The evidence file

What your entity needs to have
ready for an inspection.

The system in production is half the deliverable. The other half is the file that sustains it when the supervisor asks how you manage that process, since when, and on what evidence.

Definition

  • Traced user requirements, gathered with underwriting, claims, compliance and technology
  • Functional and design specification
  • Requirements traceability matrix
  • Risk assessment of the digitalized process

Compliance assessment

  • Mapping of the process against the technical norms applicable to your entity
  • Security and access control assessment
  • Personal data processing assessment under the Salvadoran data protection law
  • Continuity impact assessment of the process

Acceptance

  • Test and formal acceptance protocols, executable by your team
  • Test report with deviations and documented resolution
  • Training record by role
  • Operation and administration manuals

Operation

  • Change control procedure
  • Backup, recovery and continuity plan, with documented testing
  • Periodic system review plan
  • Vendor qualification dossier

Risk management is the responsibility of the entity and its board. The system does not assume it: it makes it demonstrable.

Method

Six phases, from assessment
to sustained operation.

  1. 01

    Assessment and requirements

    The process is mapped on your real formats and procedures, with underwriting, claims, compliance and technology at the same table.

  2. 02

    Architecture and proof of concept

    Architecture design, decisions on what is integrated through programming interfaces and what is not, and validation on a single line of business before committing the full scope.

  3. 03

    Construction

    Development under a documented life cycle, with version control, change traceability and progress reviews with your team.

  4. 04

    Testing and formal acceptance

    Protocols executed by your team with our support, and documented recording of deviations and their resolution.

  5. 05

    Go live and handover

    Start on one line of business or one office, parallel operation while the team consolidates, and training by role.

  6. 06

    Sustained operation

    Change control with impact assessment, documented periodic review, and engineering capacity available for whatever the regulation or the operation demands.

Qualification as a critical third party

What sustains
our own assessment.

Operational risk regulation places critical services provided by third parties inside the entity’s own risk management, which must assess, administer and monitor them. These are the elements with which we sustain that assessment, delivered as a dossier before any commitment.

Request the vendor qualification dossier

Sustaining the evidence

A system that produces regulatory evidence is not delivered and forgotten. A new line of business generates formats. A regulatory change moves a deadline or a filing. An update to the policy system can break an integration. And a supervisory review can ask for something never asked before.

That is why the project continues after go live, with engineering capacity committed by contract and response times defined for supervised processes.

Before booking

What underwriting, claims
and compliance ask.

Does it replace our policy administration system?

No. The process and evidence layer integrates with the system that already runs your portfolio. Issuance, portfolio and accounting stay where they are.

Who defines the deadlines the system watches?

Your entity does, during the requirements phase, from the applicable regulation and your own internal procedure. The system enforces them and leaves a record; it does not invent them.

Can the adjuster work without signal in the field?

Yes. Field capture works offline and synchronizes once signal returns, preserving the date and time the data was recorded, not the time it was synchronized.

Where is our policyholder data hosted?

Inside your own environment. We do not host information about your policyholders or credentials to your systems outside your infrastructure.

How do you handle health data in personal lines?

As a special category: access restricted by role, every query logged, and a personal data processing assessment delivered within the evidence file.

Does the system decide coverage or rejection?

No. Underwriting and coverage decisions belong to your authorized staff. The system enforces the control, organizes the evidence and records who decided, when, and on what basis.

Can our team modify forms without programming?

Yes, with strict segregation: whoever designs the format is not whoever fills it, and every format change goes through version control and approval.

How is the project billed?

By the scope defined after the assessment, not per user licence or per policy administered. Scope derives from the requirements you validate.

Naturaleza

Firma de ingeniería constituida, con responsabilidad contractual sobre el resultado del sistema, no solo sobre las horas entregadas.

Sedes

San Salvador, El Salvador · Barcelona, España.

Estructura de competencias

Cuatro niveles, de operación transaccional a ingeniería inversa sobre sistemas sin documentación, con el nivel de cada intervención registrado en la orden de trabajo.

Sistema de gestión

Ciclo de vida documentado, control de cambios, plan de calidad por proyecto y Protocolo de Acceso Soberano en cada compromiso.

Vendor qualification dossier

Assess us before
signing anything.

The dossier brings together the development life cycle, change control, the quality plan, the source code escrow conditions, the service continuity plan and the committed service levels. We send it so your risk and compliance team can review it with time.

A 45 minute meeting with the technical team. No commercial commitment.

Your data is processed under our privacy policy.

← Back to the general model