The file lives in three places
Part in the policy system, part in the adjuster’s inbox and part in a shared folder. Reconstructing what was resolved and on what grounds takes hours, and the result is a narrative, not a record.
We build the processes that surround your policy administration system: underwriting, issuance, first notice of loss, the policyholder complaint, the intermediary commission and the information you file with the supervisor. Data is captured where the work happens, with the clock in plain sight, so the evidence exists before anyone asks for it.
The file is incomplete. Closing is not enabled.
Close and notify Disabled
Part in the policy system, part in the adjuster’s inbox and part in a shared folder. Reconstructing what was resolved and on what grounds takes hours, and the result is a narrative, not a record.
A complaint parked while a document is awaited says nothing until it has already lapsed. Control depends on somebody opening a spreadsheet on the right day.
From form to system, from system to spreadsheet, from spreadsheet to the filing template. Every rekeying is an opportunity for a gap between what happened and what is reported.
Credential validity, settled commissions, production by channel and registered mass distributors are verified against lists that start ageing the day they are compiled.
Digitalizing an insurer’s processes is not replacing its policy administration system. The technical core, the accounting system and the document manager stay where they are, and the work integrates with them.
We do not deliver a closed product with these processes preconfigured. They are examples of the kind of process we digitalize, and every implementation is designed on your entity’s real lines of business, procedures and formats.
An insurance company is subject to the same body of technical norms on risk management, information security and business continuity as the rest of the supervised financial system. This is the mapping between what those norms require to be sustained and the control that produces it.
| Norm | Requirement | Implemented control |
|---|---|---|
| NRP-20 | Integrated risk management sustained by a formal methodology, with enough information for the board to decide and for the supervisor to review. | Structured recording of the event and the control, traceable from the source data to the report presented, with no later reconstruction. |
| NRP-42 | Operational risk management over processes, people, technology, information and external events, with systematic identification and recording of events. | Capture of the event as it happens, classification by factor and effect, evidence of treatment, and a dashboard by process and responsible unit. |
| NRP-17 | Corporate governance with defined responsibilities and a record of what each body knew and approved. | Approval authority lives in the role, is enforced at the point of decision and leaves a record of who approved, when, and on which version of the file. |
| NRP-23 | Information security management, with formal control over granting, review and revocation of access. | Role based access control against the existing corporate directory, with periodic review exportable as evidence. No parallel identity repository is created. |
| NRP-24 | A business continuity management system, sustained by impact analysis and documented testing. | Documented fallback procedure for the digitalized process, scheduled backup, and restoration testing with an archived report. |
| NRP-36 | Management of money laundering, terrorist financing and proliferation financing risk, with due diligence and retention of the evidence. | Integration with the existing prevention system, with the result of the check and its date attached to the policy or claim file. |
The complete mapping, referenced to your risk matrix and your procedures in force, is delivered as a formal assessment within the evidence file.
| Norm | Requirement | Implemented control |
|---|---|---|
| NRP-39 | Filing of insurance company information for the preparation of insurance activity statistics. | The submission is generated from the same record that operated issuance and claims, with reconciliation beforehand and proof of filing archived. |
| NRP-70 | Filing of information from the accounting system of insurance companies. | Verified interface against the accounting system, with discrepancy logging and an audit log for every submission. Every reported figure traces back to the operation that produced it. |
| NCS-011 | Constitution of the technical reserves that must be maintained. | The data feeding the calculation is captured at source, with notice date, estimate, movements and closing versioned and auditable. |
| NRP-66 | Deposit of insurance policy models. | Version control over the deposited model, with electronic approval and issuance blocked on any version not in force. |
| NRP-67 | Registration of entities that distribute insurance policies on a mass basis. | Registration of the distributor with validity, assigned portfolio and training record. Distribution is blocked once validity has expired. |
| NPS4-11 | Authorization and registration of insurance intermediaries. | Credential validity verified before portfolio assignment and before commission settlement, with advance warning of expiry. |
| NCM-03 | Transparency and disclosure of information to the user. | Proof of the information delivered to the user, with document version, channel, date and acknowledgement, retrievable from the file. |
Pension related lines and operations with the Salvadoran social security institute add their own filing requirements. The design starts from the most demanding requirement applicable to your portfolio.
Many of an insurer’s obligations are not met well or badly: they are met within the deadline or breached. A process that runs against a clock needs the clock to be part of the system.
The clock starts with the notice, not with the file being opened in the system. Every request for documentation to the policyholder is recorded with its date, because the count depends on it.
The case shows time consumed and time remaining against the deadline defined in your procedure, and escalates when it is at risk, not once it has lapsed.
The supervisor filing calendar is managed inside the system, with an assigned owner, configured lead time and proof of submission archived.
Intermediary credentials, distributor registrations, policy models and reinsurance treaties give warning before they expire, not after.
A policy file contains personal data and, in personal lines, health data. It should not live in a vendor’s infrastructure, nor depend on that vendor continuing to exist.
The system is deployed inside your infrastructure. We do not host information about your policyholders or credentials to your systems outside it.
Our access to your environment is governed by the Sovereign Access Protocol: least privilege, audited channel, no retention, revocable unilaterally by you at any time.
Sovereign Access Protocol →Each layer is replaceable without rebuilding the others. If the policy system changes tomorrow, the file, the traceability and the audit trail survive.
Complete technical documentation delivered, accessible version control, and source code escrow contractable as a clause of the agreement. We hand you a system you own.
The system in production is half the deliverable. The other half is the file that sustains it when the supervisor asks how you manage that process, since when, and on what evidence.
Risk management is the responsibility of the entity and its board. The system does not assume it: it makes it demonstrable.
The process is mapped on your real formats and procedures, with underwriting, claims, compliance and technology at the same table.
Architecture design, decisions on what is integrated through programming interfaces and what is not, and validation on a single line of business before committing the full scope.
Development under a documented life cycle, with version control, change traceability and progress reviews with your team.
Protocols executed by your team with our support, and documented recording of deviations and their resolution.
Start on one line of business or one office, parallel operation while the team consolidates, and training by role.
Change control with impact assessment, documented periodic review, and engineering capacity available for whatever the regulation or the operation demands.
Operational risk regulation places critical services provided by third parties inside the entity’s own risk management, which must assess, administer and monitor them. These are the elements with which we sustain that assessment, delivered as a dossier before any commitment.
A system that produces regulatory evidence is not delivered and forgotten. A new line of business generates formats. A regulatory change moves a deadline or a filing. An update to the policy system can break an integration. And a supervisory review can ask for something never asked before.
That is why the project continues after go live, with engineering capacity committed by contract and response times defined for supervised processes.
No. The process and evidence layer integrates with the system that already runs your portfolio. Issuance, portfolio and accounting stay where they are.
Your entity does, during the requirements phase, from the applicable regulation and your own internal procedure. The system enforces them and leaves a record; it does not invent them.
Yes. Field capture works offline and synchronizes once signal returns, preserving the date and time the data was recorded, not the time it was synchronized.
Inside your own environment. We do not host information about your policyholders or credentials to your systems outside your infrastructure.
As a special category: access restricted by role, every query logged, and a personal data processing assessment delivered within the evidence file.
No. Underwriting and coverage decisions belong to your authorized staff. The system enforces the control, organizes the evidence and records who decided, when, and on what basis.
Yes, with strict segregation: whoever designs the format is not whoever fills it, and every format change goes through version control and approval.
By the scope defined after the assessment, not per user licence or per policy administered. Scope derives from the requirements you validate.
Firma de ingeniería constituida, con responsabilidad contractual sobre el resultado del sistema, no solo sobre las horas entregadas.
San Salvador, El Salvador · Barcelona, España.
Cuatro niveles, de operación transaccional a ingeniería inversa sobre sistemas sin documentación, con el nivel de cada intervención registrado en la orden de trabajo.
Ciclo de vida documentado, control de cambios, plan de calidad por proyecto y Protocolo de Acceso Soberano en cada compromiso.
The dossier brings together the development life cycle, change control, the quality plan, the source code escrow conditions, the service continuity plan and the committed service levels. We send it so your risk and compliance team can review it with time.
A 45 minute meeting with the technical team. No commercial commitment.
Thank you. We have received your request. We will send the vendor qualification dossier to your email within the next business day.
Book a call
30 min meeting · No commitment · Email confirmation
Confirm booking
Check your email: we've sent you the details.