The case: insurer with 6 labels and a DORA deadline
A mid-sized insurer has grown through acquisitions into a group of 6 labels. Different brands, different systems, different maturity levels. Through its scale, the organisation has reached a point where the AFM will begin imposing DORA compliance requirements. An Internal Audit Function (IAF) is needed.
The board is willing: but recognises that the organisation is not yet mature enough to fully embrace the three-lines model. The first line is still being built. Risk management is fragmented across labels. Compliance is reactive and sometimes absent. And now a third line must arrive that independently assesses. The board fears it will only create friction. A legitimate concern.
The dilemma
- A full-time CAE is disproportionate: insufficient work for a permanent role, and the organisation is not culturally ready for it
- A junior auditor (because "they can handle it") lacks the C-level weight needed for conversations with board, supervisory board and regulator
- An external advisory engagement delivers an assessment with PowerPoint presentations and weighty reports: but no functioning IAF. And costs a multiple
- Doing nothing is not an option: the AFM expects substance
The pragmatic approach
Audirium is engaged as a fractional Internal Audit Function. Not with a theoretical implementation plan, but with a pragmatic approach that takes into account where the organisation currently stands. The core: 20 days of engagement to see what comes out of it. Not a large open-ended project, but a defined first phase that delivers direct value.
Three tracks, one approach
| Track | What | Why pragmatic |
|---|---|---|
| 1. Road to Compliance | Map out the DORA compliance trajectory for the AFM: what needs to be in place, when, and who owns it? | Not everything at once. Focus on what the AFM expects: not an ideal-world picture the organisation cannot deliver. Growth phases and ambition must lead. |
| 2. 6 labels, different risk profiles | Determine per label: how material is it? What risk profiles apply? Where is the greatest exposure and need? Where can we achieve quick wins? | Not every label requires the same audit intensity. Proportionality: the biggest risks get the most attention. Start where there is willingness: create pockets of success. |
| 3. Audit approach alignment | Baseline, gap analysis and quality assurance aligned to the Road to Compliance. An audit plan that grows along with it, focused on continuous improvement rather than declaring things non-compliant. | The audit plan is not a static document but a living instrument that moves with the DORA roadmap. Agile concepts introduce a rhythm that moves with the business rather than creating an alternative reality. |
How it worked: 20 days
Week 1-2: Orientation and baseline
- Stakeholder conversations with board, compliance, IT and operations per label
- DORA baseline: where does the organisation stand on the five DORA pillars (ICT risk management, incident reporting, digital resilience testing, third-party risk, information sharing)? Per entity and across the group.
- Materiality assessment per label: which entities are most relevant to the AFM? Where does the board itself see the need? How does this fit the acquisition and limited integration strategy?
Week 3-4: Gap analysis and road to compliance
- Gap analysis: per DORA pillar, the gap between current state and board/AFM expectation
- Road to compliance drafted: concrete steps, owners and deadlines per label
- Audit approach defined: which audits are needed in year one, in what sequence, with what depth?
- Quality assurance framework: how do we ensure the IAF itself meets standards?
Deliverables after 20 days
| Deliverable | Status |
|---|---|
| DORA baseline (per pillar, per label) | Completed and presented to the board |
| Materiality assessment per label | Validated: 3 labels high, 1 medium, 2 low |
| Road to Compliance (DORA/AFM) | Delivered with timeline and owners |
| Gap analysis | Per label and at group level, per DORA pillar, including prioritisation |
| Risk-based audit plan year 1 | Approved by the board |
| IAF charter (proportionate) | Established: fitted to current maturity |
| QA framework | Base version operational |
Why it works
After 20 days, the organisation does not have a report about how things should be. It has a working starting point: an IAF suited to current maturity, a realistic road to compliance, and an audit plan that grows as the organisation matures. No focus on reports declaring things non-compliant: action-driven communication aimed at growth and improvement.
No overengineered three-lines model that no one understands. No 200-page DORA assessment that ends up in a drawer. A pragmatic foundation that passes the AFM test and gives the organisation something to build on.
The board member: "We did not need to be perfect. We needed to show we understand where we stand and where we are going. That is what we have now."
The difference
| Audirium (20 days) | Traditional advisory | |
|---|---|---|
| Timeline | 4 weeks | 12-16 weeks |
| Output | Working IAF + road to compliance | Assessment report + recommendations |
| Implementation | Ready to use | Separate follow-up engagement |
| Proportionality | Tailored to maturity | Based on best practice (ideal scenario) |
| Costs | Fixed upfront | Open-ended, scope creep common |
| Follow-up | Flexible scale up/down | New project per phase |